PT-2026-49221 · WordPress · More Fields Plugin

CVE-2016-20083

·

Published

2026-06-15

·

Updated

2026-06-15

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions WordPress More Fields Plugin version 2.1
Description Cross-site request forgery (CSRF) occurs when a web application allows an attacker to induce a user to perform actions they do not intend to. This issue allows attackers to perform unauthorized actions by disabling CSRF token validation. By crafting malicious web pages, attackers can trick logged-in administrators into adding or deleting custom fields and boxes on the Write/Edit page through POST and GET requests to the 'options-general.php' endpoint.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-20083

Affected Products

More Fields Plugin