CVE-2016-20083

MEDIUM

WordPress More Fields Plugin 2.1 Cross-Site Request Forgery

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2016-20083. PoCs published by Aatif Shahdad.

AI-analyzed exploit summary This exploit demonstrates a CSRF vulnerability in the WordPress More Fields Plugin 2.1, allowing an attacker to add or delete boxes via crafted HTML forms without CSRF token validation.

Description

WordPress More Fields Plugin 2.1 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions by disabling CSRF token validation. Attackers can craft malicious web pages that trick logged-in administrators into adding or deleting custom fields and boxes on the Write/Edit page via POST and GET requests to the options-general.php endpoint.

Exploits (1)

exploitdb WORKING POC
by Aatif Shahdad · textwebappsphp
https://www.exploit-db.com/exploits/39507

This exploit demonstrates a CSRF vulnerability in the WordPress More Fields Plugin 2.1, allowing an attacker to add or delete boxes via crafted HTML forms without CSRF token validation.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: WordPress More Fields Plugin 2.1
Auth required
Prerequisites: Admin session in the target WordPress instance
devstral-2 · analyzed Jun 15, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit exploit
ExploitDB-39507
https://www.exploit-db.com/exploits/39507
Product product
Product Reference
https://wordpress.org/support/plugin/more-fields
Third Party Advisory third-party-advisory
VulnCheck Advisory: WordPress More Fields Plugin 2.1 Cross-Site Request Forgery
https://www.vulncheck.com/advisories/wordpress-more-fields-plugin-cross-site-request-forgery

Scores

CVSS v3 5.3
EPSS 0.0014
EPSS Percentile 3.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-352
Status published
Products (1)
henrikmelin/More Fields 2.1
Published Jun 15, 2026
Tracked Since Jun 15, 2026