PT-2026-49212 · WordPress · Lazy Content Slider Plugin
CVE-2016-20074
·
Published
2026-06-15
·
Updated
2026-06-15
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
WordPress Lazy Content Slider Plugin version 3.4
Description
Cross-site request forgery (CSRF) allows attackers to perform unauthorized actions by crafting malicious HTML forms. Authenticated administrators can be tricked into submitting POST requests to the plugin settings page via the 'lzcs admin.php' endpoint to modify configuration parameters such as
lzcs color and lzcs count.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lazy Content Slider Plugin