The Quran Translations plugin for WordPress versions up to 1.7 contains a Cross-Site Request Forgery vulnerability in the quran_playlist_options() function due to missing nonce validation. An unauthenticated attacker can forge requests to modify plugin settings, including display options for PDF, RSS, podcast, and media player features, provided they can trick a site administrator into clicking a malicious link. The vulnerability requires user interaction and carries a CVSS score of 4.3 (Medium severity) with no confidentiality impact but potential for integrity compromise. Exploitation is extremely unlikely at present, with no active exploitation reported, no public exploit code availability, and minimal community attention as reflected in its low EPSS score of 0.00014. The vulnerability is not currently listed on CISA's Known Exploited Vulnerabilities catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Edckwt | Quran Translations | >= 0, <= 1.7CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.