Description
WordPress Plugin Custom Field Suite is prone to a cross-site request forgery vulnerability. Exploiting this issue may allow a remote attacker to perform certain administrative actions and gain unauthorized access to the affected application; other attacks are also possible. WordPress Plugin Custom Field Suite version 2.5.15 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.5.16 or latest
References
Related Vulnerabilities
WordPress Plugin Product Size charts for Woocommerce Unspecified Vulnerability (1.0)
WordPress Plugin LearnPress-WordPress LMS Cross-Site Scripting (4.1.6.5)
WordPress Plugin All-In-One Security (AIOS)-Security and Firewall Directory Traversal (5.1.4)
WordPress Plugin All-in-One Event Calendar Multiple Vulnerabilities (2.3.12)