Vulnerability Description
WordPress More Fields Plugin 2.1 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions by disabling CSRF token validation. Attackers can craft malicious web pages that trick logged-in administrators into adding or deleting custom fields and boxes on the Write/Edit page via POST and GET requests to the options-general.php endpoint.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://wordpress.org/support/plugin/more-fields
- https://www.exploit-db.com/exploits/39507
- https://www.vulncheck.com/advisories/wordpress-more-fields-plugin-cross-site-req
FAQ
What is CVE-2016-20083?
CVE-2016-20083 is a vulnerability with a CVSS score of 5.3 (MEDIUM). WordPress More Fields Plugin 2.1 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions by disabling CSRF token validation. Attackers can craft malic...
How severe is CVE-2016-20083?
CVE-2016-20083 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-20083?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.