CVE-2020-36740
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Jul 1, 2023
Updated: Nov 7, 2023
CWE ID 352
Summary
CVE-2020-36740 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the Radio Buttons for Taxonomies plugin for WordPress. Versions up to and including 2.0.5 are susceptible to this issue. The root cause is a lack of proper nonce validation in the save_single_term() function, which allows unauthenticated attackers to save terms through a maliciously crafted request. Successful exploitation hinges on tricking a site administrator into performing a specific action, such as clicking on a malicious link.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share