Cross-Site Request Forgery (CSRF) vulnerability in lizeipe Flash News / Post (Responsive) flashnews-fading-effect-pearlbells allows Privilege Escalation.This issue affects Flash News / Post (Responsive): from n/a through <= 4.1.
The CSRF vulnerability (CWE-352) consists of the lack of proper verification of the source of HTTP requests directed at sensitive plugin functions. An attacker can prepare a malicious website that sends a forged request to the victim's WordPress panel in the background. If a logged-in user (e.g., administrator) visits this site, the request will be executed with their privileges without their knowledge, leading to privilege escalation for the attacker.
An attacker can gain elevated privileges in the WordPress system, potentially taking full control of the website, including the ability to modify content, install backdoors, or take over administrator accounts.
The Flash News / Post (Responsive) plugin should be updated to a version higher than 4.1. If an update is not available, the plugin should be deactivated and removed. Detailed information is available in the Patchstack database at the indicated reference address.
WordPress plugin Flash News / Post (Responsive) (slug: flashnews-fading-effect-pearlbells) by lizeipe, versions from n/a to 4.1 inclusive.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H