CVE-2016-20074

MEDIUM

WordPress Lazy Content Slider Plugin 3.4 CSRF

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2016-20074. PoCs published by Persian Hack Team.

AI-analyzed exploit summary This exploit demonstrates a CSRF vulnerability in the WordPress Lazy Content Slider plugin (version 3.4). The PoC provides an HTML form that submits a crafted POST request to the vulnerable endpoint, allowing an attacker to perform unauthorized actions on behalf of an authenticated user.

Description

WordPress Lazy Content Slider Plugin 3.4 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions by crafting malicious HTML forms. Attackers can trick authenticated administrators into submitting POST requests to the plugin settings page via lzcs_admin.php to modify plugin configuration parameters like lzcs_color and lzcs_count.

Exploits (1)

exploitdb WORKING POC
by Persian Hack Team · textwebappsphp
https://www.exploit-db.com/exploits/40070

This exploit demonstrates a CSRF vulnerability in the WordPress Lazy Content Slider plugin (version 3.4). The PoC provides an HTML form that submits a crafted POST request to the vulnerable endpoint, allowing an attacker to perform unauthorized actions on behalf of an authenticated user.

Classification
Working Poc 90%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target: WordPress Lazy Content Slider Plugin 3.4
Auth required
Prerequisites: Victim must be authenticated in WordPress · Attacker must trick victim into visiting malicious HTML page
devstral-2 · analyzed Jun 15, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit exploit
ExploitDB-40070
https://www.exploit-db.com/exploits/40070
Third Party Advisory third-party-advisory
VulnCheck Advisory: WordPress Lazy Content Slider Plugin 3.4 CSRF
https://www.vulncheck.com/advisories/wordpress-lazy-content-slider-plugin-csrf

Scores

CVSS v3 4.3
EPSS 0.0011
EPSS Percentile 1.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-352
Status published
Products (1)
leethompson/Lazy Content Slider Plugin 3.4
Published Jun 15, 2026
Tracked Since Jun 15, 2026