CVE · High

CVE-2020-8417 — Code Snippets [code-snippets] < 2.14.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2020-8417 Code Snippets [code-snippets] < 2.14.0 Cross-Site Request Forgery (CSRF) High 8.8 < 2.14.0 2.14.0 2020-01-28

CVE-2020-8417

The Code Snippets WordPress plugin in version 2.13.3 and earlier contains a cross-site request forgery vulnerability that can be leveraged to achieve remote code execution. An attacker can exploit a missing CSRF protection mechanism to trick an authenticated user into performing unintended actions that result in arbitrary code execution on the affected WordPress installation. The vulnerability was discovered by Chloe Chamberland and affects all versions up to and including 2.13.3, with fixes available in version 2.14.0 and later.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.