Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2016-6897Cross-Site Request Forgery in Wordpress

Severity
6.5MEDIUMNVD
OSV7.1
EPSS
30.3%
top 3.30%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedJan 18
Latest updateMay 17

Description

Cross-site request forgery (CSRF) vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress before 4.6 allows remote attackers to hijack the authentication of subscribers for /dev/random read operations by leveraging a late call to the check_ajax_referer function, a related issue to CVE-2016-6896.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages3 packages

debiandebian/wordpress< wordpress 4.6.1+dfsg-1 (bookworm)
Debianwordpress/wordpress< 4.6.1+dfsg-1+3

🔴Vulnerability Details

2
GHSA
GHSA-rxch-vxwr-47jw: Cross-site request forgery (CSRF) vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions2022-05-17
OSV
CVE-2016-6897: Cross-site request forgery (CSRF) vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions2017-01-18

💥Exploits & PoCs

2
Exploit-DB
WordPress Core 4.5.3 - Directory Traversal / Denial of Service2016-08-22
Metasploit
WordPress Traversal Directory DoS

📋Vendor Advisories

1
Debian
CVE-2016-6897: wordpress - Cross-site request forgery (CSRF) vulnerability in the wp_ajax_update_plugin fun...2016

💬Community

4
Bugzilla
Path Traversal Vulnerability in Mozilla WP-Engine Wordpress 4.5.32016-09-08
Bugzilla
CVE-2016-6896 CVE-2016-6897 wordpress: Multiple vulnerabilities fixed in wordpress 4.62016-08-22
Bugzilla
CVE-2016-6896 CVE-2016-6897 wordpress: Multiple vulnerabilities fixed in wordpress 4.6 [fedora-all]2016-08-22
Bugzilla
CVE-2016-6896 CVE-2016-6897 wordpress: Multiple vulnerabilities fixed in wordpress 4.6 [epel-all]2016-08-22
CVE-2016-6897 — Cross-Site Request Forgery in Wordpress | cvebase