Exploitation Summary
EIP tracks 1 public exploit for CVE-2016-20074. PoCs published by Persian Hack Team.
AI-analyzed exploit summary This exploit demonstrates a CSRF vulnerability in the WordPress Lazy Content Slider plugin (version 3.4). The PoC provides an HTML form that submits a crafted POST request to the vulnerable endpoint, allowing an attacker to perform unauthorized actions on behalf of an authenticated user.
Description
WordPress Lazy Content Slider Plugin 3.4 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions by crafting malicious HTML forms. Attackers can trick authenticated administrators into submitting POST requests to the plugin settings page via lzcs_admin.php to modify plugin configuration parameters like lzcs_color and lzcs_count.
Exploits (1)
This exploit demonstrates a CSRF vulnerability in the WordPress Lazy Content Slider plugin (version 3.4). The PoC provides an HTML form that submits a crafted POST request to the vulnerable endpoint, allowing an attacker to perform unauthorized actions on behalf of an authenticated user.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N