#VU26085 Cross-site request forgery in WPML Multilingual CMS - CVE-2020-10568
Published: March 16, 2020
WPML Multilingual CMS
OnTheGoSystems
Description
The vulnerability allows a remote attacker to perform cross-site request forgery attacks.
The vulnerability exists due to a loose comparison in the "installer_download_plugin" action. A remote authenticated attacker can trick the victim to visit a specially crafted web page and perform arbitrary actions on behalf of the victim on the vulnerable website, such as execute arbitrary code on the target system.