Impact
The vulnerability permits an unauthenticated attacker to craft requests that trigger actions in the PublishPress Series plugin without user permission. Because the flaw lies in inadequate request validation (CWE-352), an attacker can create, modify, or delete series data, potentially disrupting content organization and workflow. The impact applies to the integrity of the site’s content structure and may lead to misinformation or loss of work if critical series are altered.
Affected Systems
PublishPress Series plugin for WordPress. All installations of version 3.1.3 or earlier are affected. Users should verify the plugin version and update if necessary.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited publicly known exploitation. Since the flaw is a CSRF, the likely attack vector is a crafted HTTP request sent to the plugin’s endpoints, possibly using a victim’s logged‑in session. No local privilege escalation or remote code execution is involved, but the ability to change series can have significant operational consequences.
OpenCVE Enrichment