WordPress Lazy Content Slider Plugin 3.4 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions by crafting malicious HTML forms. Attackers can trick authenticated administrators into submitting POST requests to the plugin settings page via lzcs_admin.php to modify plugin configuration parameters like lzcs_color and lzcs_count.
Metrics
Affected Vendors & Products
References
History
Mon, 15 Jun 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 15 Jun 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WordPress Lazy Content Slider Plugin 3.4 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions by crafting malicious HTML forms. Attackers can trick authenticated administrators into submitting POST requests to the plugin settings page via lzcs_admin.php to modify plugin configuration parameters like lzcs_color and lzcs_count. | |
| Title | WordPress Lazy Content Slider Plugin 3.4 CSRF | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-15T16:34:09.967Z
Reserved: 2026-06-15T11:41:35.776Z
Link: CVE-2016-20074
Updated: 2026-06-15T16:34:06.130Z
Status : Received
Published: 2026-06-15T14:16:30.663
Modified: 2026-06-15T14:16:30.663
Link: CVE-2016-20074
No data.
OpenCVE Enrichment
No data.