Code Snippets < 2.14.0 - Cross-Site Request Forgery via Import Menu
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2020-8417. PoCs published by waleweewe12, Vulnmachines, Rapidsafeguard.
AI-analyzed exploit summary This repository contains a functional exploit PoC for CVE-2020-8417, targeting the Code Snippets plugin for WordPress. It includes a Docker Compose setup to replicate a vulnerable environment and the plugin's source code, demonstrating the vulnerability in a controlled manner.
Description
The Code Snippets plugin before 2.14.0 for WordPress allows CSRF because of the lack of a Referer check on the import menu.
Exploits (3)
This repository contains a functional exploit PoC for CVE-2020-8417, targeting the Code Snippets plugin for WordPress. It includes a Docker Compose setup to replicate a vulnerable environment and the plugin's source code, demonstrating the vulnerability in a controlled manner.
The repository lacks exploit code and only contains a README with social media links and a YouTube video reference, which is typical of suspicious repos aiming to redirect users elsewhere.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H