Impact
The Search Analytics for WP plugin for WordPress is vulnerable to CSRF because the process_bulk_action() function of MWTSA_Stats_Table does not perform proper nonce validation. An attacker who can trick a user with dashboard access into clicking a forged link can delete arbitrary search‑term records and associated search‑history rows without authentication. The primary impact is loss of data integrity for the site’s search analytics.
Affected Systems
Affected product is the Search Analytics for WP plugin, versions 1.4.16 and earlier. The plugin is distributed by the vendor cornelraiu-1 and provides a dashboard that administrators access to view and manage search statistics.
Risk and Exploitability
The CVSS score of 8.1 indicates a high‑severity flaw. Exploitation requires the user to click on a malicious link, representing a typical HTTP CSRF attack vector. The EPSS score is unavailable, and the vulnerability is not listed in the CISA KEV catalog. Because any unauthenticated attacker can trigger the deletion by coercing an authenticated user, the risk remains elevated and the threat is significant for sites that rely on accurate search history data.
OpenCVE Enrichment