Impact
The vulnerability arises from missing or incorrect nonce validation in the cmac_campaigns_action function, allowing any unauthenticated user to forge requests that permanently delete advertising campaigns, associated banner records, and uploaded files. This leads to data loss and possible service disruption for sites using the compromised plugin. The weakness corresponds to the Common Weakness Enumeration CWE-352: Cross‑Site Request Forgery.
Affected Systems
Plugins affected are CM Ad Changer versions up to and including 2.0.7, deployed on WordPress sites. Owners of these installations, regardless of operating system, are at risk if the plugin remains at these versions.
Risk and Exploitability
The CVSS base score of 4.3 indicates a moderate impact. The EPSS score is currently not available, so the precise exploitation probability is unknown, and the vulnerability does not appear in the CISA KEV catalog. The attack vector requires a privileged administrator to click a crafted link or submit a crafted form; the attacker cannot directly execute code from their side. Social engineering to lure the administrator into performing the request is therefore necessary, limiting the pool of effective attackers to those capable of reaching administrative staff.
OpenCVE Enrichment