Description
WordPress before 5.5.2 allows CSRF attacks that change a theme's background image.
Remediation
References
Related Vulnerabilities
WordPress Plugin BackWPup Multiple Unspecified Vulnerabilities (3.2.1)
WordPress Plugin InstaWP Connect-1-click WP Staging & Migration Security Bypass (0.1.0.38)
WordPress Plugin All Video Gallery 'vid' Parameter Multiple SQL Injection Vulnerabilities (1.1)
PHP Permissions, Privileges, and Access Controls Vulnerability (CVE-2007-4850)