High severity8.8NVD Advisory· Published Aug 7, 2016· Updated May 6, 2026
CVE-2016-6635
CVE-2016-6635
Description
Cross-site request forgery (CSRF) vulnerability in the wp_ajax_wp_compression_test function in wp-admin/includes/ajax-actions.php in WordPress before 4.5 allows remote attackers to hijack the authentication of administrators for requests that change the script compression option.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- github.com/WordPress/WordPress/commit/9b7a7754133c50b82bd9d976fb5b24094f658aabnvdPatch
- wpvulndb.com/vulnerabilities/8475nvdThird Party AdvisoryVDB Entry
- codex.wordpress.org/Version_4.5nvdRelease Notes
- www.debian.org/security/2016/dsa-3681nvd
News mentions
0No linked articles in our index yet.