Cross-site request forgery (CSRF) is a vulnerability in a feature of WordPress before version 4.7.1 that allows remote attackers to gain access to someone else’s account without their knowledge. This is done by performing certain actions related to widgets-access in the widget-editing accessibility-mode.