CVE-2020-29458

Textpattern CMS 4.6.2 allows CSRF via the prefs subsystem.