Medium severity5.3NVD Advisory· Published Jun 15, 2026· Updated Jun 15, 2026
CVE-2016-20083
CVE-2016-20083
Description
WordPress More Fields Plugin 2.1 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions by disabling CSRF token validation. Attackers can craft malicious web pages that trick logged-in administrators into adding or deleting custom fields and boxes on the Write/Edit page via POST and GET requests to the options-general.php endpoint.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2(expand)+ 1 more
- (no CPE)
- (no CPE)range: =2.1
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.