The bug was discovered in March 2018. It was reported to vendor via email, via Facebook private message and via contact form. In a real attack, the form can be made to autosubmit. The bug has been fixed and the plugin is now available for download on wordpress.org.com and the vendor has made a fix for the bug. You can read more about CVSS base scores on Wikipedia or in the CVSS specification. The bug is currently being investigated by the vendor.”]
Source: https://advisories.dxw.com/advisories/csrf-in-tooltipy/

