Description WordPress before 5.5.2 allows CSRF attacks that change a theme's background image. Remediation References CVE-2020-28040 Related Vulnerabilities WebLogic CVE-2021-2142 Vulnerability (CVE-2021-2142) Oracle JRE CVE-2024-20952 Vulnerability (CVE-2024-20952) WordPress Plugin Toolset Types-Custom Post Types, Custom Fields and Taxonomies Multiple Unspecified Vulnerabilities (2.2.2) Liferay DXP Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2024-8980) PHP-Fusion Improper Privilege Management Vulnerability (CVE-2020-24949) Severity Medium Classification CVE-2020-28040 CWE-352 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N Tags Missing Update Known Vulnerabilities