CVE-2020-8417
The Code Snippets WordPress plugin in version 2.13.3 and earlier contains a cross-site request forgery vulnerability that can be leveraged to achieve remote code execution. An attacker can exploit a missing CSRF protection mechanism to trick an authenticated user into performing unintended actions that result in arbitrary code execution on the affected WordPress installation. The vulnerability was discovered by Chloe Chamberland and affects all versions up to and including 2.13.3, with fixes available in version 2.14.0 and later.
Based on public CVE data (MITRE/NVD).