Cross-Site Request Forgery Vulnerability in WordPress CP Polls by WordPress
CVE-2016-20067
Key Information:
Badges
What is CVE-2016-20067?
WordPress CP Polls version 1.0.8 is susceptible to a cross-site request forgery (CSRF) vulnerability. This flaw permits attackers to craft malicious HTML pages that can execute unauthorized poll actions when visited by authenticated administrators. If an administrator inadvertently accesses such a page, it can lead to unwanted operations being performed in the context of their account, posing a significant risk to the integrity of the polls managed through this plugin.
Affected Version(s)
CP Polls 1.0.8
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved