PT-2026-49221 · WordPress · More Fields Plugin
CVE-2016-20083
·
Published
2026-06-15
·
Updated
2026-06-15
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
WordPress More Fields Plugin version 2.1
Description
Cross-site request forgery (CSRF) occurs when a web application allows an attacker to induce a user to perform actions they do not intend to. This issue allows attackers to perform unauthorized actions by disabling CSRF token validation. By crafting malicious web pages, attackers can trick logged-in administrators into adding or deleting custom fields and boxes on the Write/Edit page through POST and GET requests to the 'options-general.php' endpoint.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
More Fields Plugin