CVE-2016-20083

WordPress More Fields Plugin 2.1 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions by disabling CSRF token validation. Attackers can craft malicious web pages that trick logged-in administrators into adding or deleting custom fields and boxes on the Write/Edit page via POST and GET requests to the options-general.php endpoint.
Configurations

No configuration.

History

No history.

Information

Published : 2026-06-15 14:16

Updated : 2026-06-17 00:43


NVD link : CVE-2016-20083

Mitre link : CVE-2016-20083

CVE.ORG link : CVE-2016-20083


JSON object : View

Products Affected

No product.

CWE
CWE-352

Cross-Site Request Forgery (CSRF)