Impact
The EmergencyWP – Dead Man's switch & legacy deliverance plugin contains a Cross‑Site Request Forgery flaw caused by missing or incorrect nonce validation in the settings save handler. An attacker can forge a request that forces an administrator to trigger a configuration change, enabling adjustments to the minimum access role, capability modification, data‑erasure flags, life‑check timing, mandatory email address, confirmation page ID, and date formats. These changes effectively give the attacker the ability to alter WordPress role capabilities and system behavior without authorization, thus elevating their privileges or compromising site integrity.
Affected Systems
All WordPress sites utilizing the EmergencyWP plugin version 1.4.2 or lower from the planetshaker vendor are impacted. The affected range covers each release up to including 1.4.2; newer releases are not listed as vulnerable.
Risk and Exploitability
The vulnerability scores a CVSS of 4.3, placing it in the moderate severity range, and it is not listed in CISA’s KEV catalog. Attackers can exploit the flaw via a simple forged link or script that an administrator unknowingly clicks, bypassing authentication checks. Because the susceptibility requires an admin interaction, the EPSS score is not available, but the ease of crafting a CSRF request and the potential for privilege escalation make it a relevant risk for compromised or dozen sites that still use the old plugin version.
OpenCVE Enrichment