CVE-2016-20083
MEDIUMWordPress More Fields Plugin 2.1 Cross-Site Request Forgery
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2016-20083. PoCs published by Aatif Shahdad.
AI-analyzed exploit summary This exploit demonstrates a CSRF vulnerability in the WordPress More Fields Plugin 2.1, allowing an attacker to add or delete boxes via crafted HTML forms without CSRF token validation.
Description
WordPress More Fields Plugin 2.1 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions by disabling CSRF token validation. Attackers can craft malicious web pages that trick logged-in administrators into adding or deleting custom fields and boxes on the Write/Edit page via POST and GET requests to the options-general.php endpoint.
Exploits (1)
This exploit demonstrates a CSRF vulnerability in the WordPress More Fields Plugin 2.1, allowing an attacker to add or delete boxes via crafted HTML forms without CSRF token validation.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N