Copymatic
cpe:2.3:a:copymatic:copymatic:*:*:*:*:wordpress:*:*
- <= 2.1
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Copymatic – AI Content Writer & Generator plugin for WordPress, affecting all versions through 2.1. The vulnerability arises from inadequate nonce validation on the 'copymatic-menu' page, allowing unauthenticated attackers to update the 'copymatic_apikey' option. Exploitation requires tricking a site administrator into clicking a link that initiates the forged request.
Exploitation of this vulnerability allows for Cross-Site Request Forgery, enabling attackers to manipulate plugin settings by updating the 'copymatic_apikey' option without proper authorization.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.