Description WordPress before 5.5.2 allows CSRF attacks that change a theme's background image. Remediation References CVE-2020-28040 Related Vulnerabilities Dot CMS Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2016-2355) Drupal Core 4.7.x Cross-Site Request Forgery (4.7.0 - 4.7.10) WordPress Plugin YITH WooCommerce Product Add-Ons Multiple Vulnerabilities (2.0.7) Dot CMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2016-3971) WordPress Plugin Shop Page WP Cross-Site Scripting (1.2.7) Severity Medium Classification CVE-2020-28040 CWE-352 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N Tags Missing Update Known Vulnerabilities