Description WordPress before 5.5.2 allows CSRF attacks that change a theme's background image. Remediation References CVE-2020-28040 Related Vulnerabilities WordPress Plugin Simple Feature Requests Free Unspecified Vulnerability (1.0.4) WordPress Plugin Click to Call or Chat Buttons Cross-Site Scripting (1.4.0) Oracle JRE CVE-2018-2798 Vulnerability (CVE-2018-2798) WordPress Plugin Essential Content Types Security Bypass (1.8.6) WordPress Plugin Ultimate Coming Soon, Maintenance Mode for WordPress-Everest Coming Soon Lite includes Backdoor [Only if downloaded via the vendor website] (1.1.0) Severity Medium Classification CVE-2020-28040 CWE-352 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N Tags Missing Update Known Vulnerabilities