Junglewise Threat Intelligence

CVE-2016-20074: WordPress Lazy Content Slider CSRF in lzcs_admin.php

CVE-2016-20074 · Severity: medium · CVSS 4.3 · Published 2026-06-15

Vendors: Wordpress.

Executive brief

The Lazy Content Slider plugin for WordPress, which is used to create sliding content displays on websites, contains a security flaw that allows unauthorized configuration changes. By tricking a logged-in administrator into clicking a malicious link or visiting a compromised webpage, an attacker can remotely modify plugin settings such as display colors and content counts. This could lead to unauthorized alterations of the website's appearance or functionality without the administrator's knowledge.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Lazy Content Slider Plugin version 3.4. The vulnerability is located in the lzcs_admin.php component, which fails to implement proper nonce validation or request verification for administrative actions. An attacker can exploit this by crafting a malicious HTML form that targets the plugin's settings page. If an authenticated administrator is induced to submit this request (typically via social engineering or a malicious site), the attacker can modify configuration parameters such as 'lzcs_color' and 'lzcs_count'. This allows for unauthorized modification of plugin data and site behavior. Public proof-of-concept exploits have been documented in Exploit-DB.

Affected products

  • WordPress Lazy Content Slider Plugin 3.4

Timeline

  • 2016-07-08: disclosed: Initial exploit published on Exploit-DB
  • 2026-06-15: advisory: CVE-2016-20074 published/updated in NVD via VulnCheck

References