CVE Feed

    Dashboard / CVE / CVE-2016-6897

    CVE-2016-6897

    Cross-site request forgery (CSRF) vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress before 4.6 allows remote attackers to hijack the authentication of subscribers for /dev/random read operations by leveraging a late call to the check_ajax_referer function, a related issue to CVE-2016-6896.

    Published:Jan 18, 2017
    Last Modified:Apr 20, 2025
    EPS:Jan 18, 2017
    EPSS Score:0.29012
    CVSS Score:6.5

    Affected Products

    Vendor
    Wordpress
    Product
    Wordpress

    Related CVEs

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High