CVE-2016-6897: CSRF
Cross-site request forgery (CSRF) vulnerability in the wpajaxupdateplugin function in wp-admin/includes/ajax-actions.php in WordPress before 4.6 allows remote attackers to hijack the authentication of subscribers for /dev/random read operations by leveraging a late call to the checkajaxreferer function, a related issue to CVE-2016-6896.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6897?
CVE-2016-6897 has a medium severity rating due to the potential for cross-site request forgery attacks.
How do I fix CVE-2016-6897?
To fix CVE-2016-6897, upgrade to WordPress version 4.6 or later.
Who is affected by CVE-2016-6897?
CVE-2016-6897 affects all versions of WordPress prior to 4.6, especially impacting sites with subscriber-level users.
What types of attacks can CVE-2016-6897 enable?
CVE-2016-6897 can enable remote attackers to hijack the authentication of subscribers via CSRF.
Can CVE-2016-6897 be exploited without user interaction?
Yes, CVE-2016-6897 can be exploited by an attacker without needing user interaction, making it a serious risk.