CVE-2020-13426
WordPress vulnerability analysis and mitigation

Overview

The Multi-Scheduler plugin version 1.0.0 for WordPress contains a Cross-Site Request Forgery (CSRF) vulnerability (CVE-2020-13426). The vulnerability was discovered on May 21, 2020, and affects the forms presented by the plugin, which lack proper CSRF protection mechanisms. The plugin was designed to manage event reservations, including appointments, meetings, and interviews, with calendar functionality and user management capabilities (CX Security, Infayer).

Technical details

The vulnerability stems from the absence of anti-CSRF tokens in forms that handle user deletion and creation operations. This security oversight places complete trust in user actions without proper validation. The CVSS v3.1 base score is 6.5 (MEDIUM) with a vector string of CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N, indicating a network-accessible vulnerability requiring user interaction (NVD).

Impact

The vulnerability allows attackers to force authenticated users to perform unintended actions, specifically the deletion of user records from the 'professional' table in the application database when the target user ID is known. This can lead to unauthorized deletion of user data without the victim's consent (CX Security, Infayer).

Exploitability

Proof of Concept (PoC) exploits have been published demonstrating how an attacker can craft a malicious form that, when submitted by an authenticated user, triggers the unauthorized deletion of user records. The vulnerability has been documented in multiple security databases and exploit repositories (Exploit DB, Packet Storm).

Mitigation and workarounds

The plugin has been closed and is no longer available for download as of June 1, 2020, due to this security issue. Users are advised to remove the plugin from their WordPress installations to prevent potential exploitation (WordPress).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-78570CRITICAL9.8
  • totaldonations
NoNoAug 25, 2026
CVE-2026-78568CRITICAL9.8
  • totaldonations
NoNoAug 25, 2026
CVE-2026-78572HIGH8.1
  • kalles-addons
NoNoAug 25, 2026
CVE-2026-78576HIGH7.5
  • readabler
NoYesAug 25, 2026
CVE-2026-76128MEDIUM6.4
  • ecommerce-product-catalog
NoYesAug 25, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management