CVE-2020-23837: Multi User Project Multi User

High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.

A Cross-Site Request Forgery (CSRF) vulnerability in the Multi User plugin 1.8.2 for GetSimple CMS allows remote attackers to add admin (or other) users after an authenticated admin visits a third-party site or clicks on a URL.

Affected products

Published 2020-09-25. Last modified 2026-06-17.