← Back
CWE-352

9,673 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium

Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

JSON object

Loading...

CVEs (9,673)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Toolbar To Share Project
1Toolbar To Share
Jun 17, 2026
Jun 13, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The ToolBar to Share plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0. This is due to missing nonce validation on the plugin_toolbar_comparte page. This makes it poss...Show more
The ToolBar to Share plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0. This is due to missing nonce validation on the plugin_toolbar_comparte page. This makes it possible for unauthenticated attackers to update the plugins settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.Show less
1Copify
1Copify
Jun 17, 2026
Jun 13, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The Copify plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.0. This is due to missing nonce validation on the CopifySettings page. This makes it possible for unauthen...Show more
The Copify plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.0. This is due to missing nonce validation on the CopifySettings page. This makes it possible for unauthenticated attackers to update the plugins settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.Show less
1Private Files Project
1Private Files
Jun 17, 2026
Jun 13, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The Private Files WordPress plugin through 0.40 is missing CSRF check when disabling the protection, which could allow attackers to make a logged in admin perform such action via a CSRF attack and make the blog public
1Quick Subscribe Project
1Quick Subscribe
Jun 17, 2026
Jun 13, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Quick Subscribe WordPress plugin through 1.7.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and leading to Stored X...Show more
The Quick Subscribe WordPress plugin through 1.7.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and leading to Stored XSS due to the lack of sanitisation and escaping in some of themShow less
1One Click Plugin Updater Project
1One Click Plugin Updater
Jun 17, 2026
Jun 13, 2022
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
The One Click Plugin Updater WordPress plugin through 2.4.14 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and disable /...Show more
The One Click Plugin Updater WordPress plugin through 2.4.14 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and disable / hide the badge of the available updates and the related check.Show less
1New User Email Set Up Project
1New User Email Set Up
Jun 17, 2026
Jun 13, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The New User Email Set Up WordPress plugin through 0.5.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
1Change Uploaded File Permissions Project
1Change Uploaded File Permissions
Jun 17, 2026
Jun 13, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Due to missing checks the Change Uploaded File Permissions WordPress plugin through 4.0.0 is vulnerable to CSRF attacks. This can be used to change the file and folder permissions of any folder. This could be problematic...Show more
Due to missing checks the Change Uploaded File Permissions WordPress plugin through 4.0.0 is vulnerable to CSRF attacks. This can be used to change the file and folder permissions of any folder. This could be problematic when specific files like ini files are made readable for everyone due to this.Show less
1Sideblog Project
1Sideblog
Jun 17, 2026
Jun 13, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Sideblog WordPress plugin through 6.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-Site Sc...Show more
The Sideblog WordPress plugin through 6.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-Site Scripting due to the lack of sanitisation and escapingShow less
1Posttabs Project
1Posttabs
Jun 17, 2026
Jun 13, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The postTabs WordPress plugin through 2.10.6 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack, which also lead to Stored Cr...Show more
The postTabs WordPress plugin through 2.10.6 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack, which also lead to Stored Cross-Site Scripting due to the lack of sanitisation and escapingShow less
1Latex Project
1Latex
Jun 17, 2026
Jun 13, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The LaTeX for WordPress plugin through 3.4.10 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack which could also lead to Sto...Show more
The LaTeX for WordPress plugin through 3.4.10 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack which could also lead to Stored Cross-Site Scripting due to the lack of sanitisation and escapingShow less
1Auto Delete Posts Project
1Auto Delete Posts
Jun 17, 2026
Jun 13, 2022
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
The Auto Delete Posts WordPress plugin through 1.3.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and delete specific p...Show more
The Auto Delete Posts WordPress plugin through 1.3.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and delete specific posts, categories and attachments at once.Show less
1Hot Linked Image Cacher Project
1Hot Linked Image Cacher
Jun 17, 2026
Jun 13, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The Hot Linked Image Cacher WordPress plugin through 1.16 is vulnerable to CSRF. This can be used to store / cache images from external domains on the server, which could lead to legal risks (due to copyright violations...Show more
The Hot Linked Image Cacher WordPress plugin through 1.16 is vulnerable to CSRF. This can be used to store / cache images from external domains on the server, which could lead to legal risks (due to copyright violations or licensing rules).Show less
1Wp Chgfontsize Project
1Wp Chgfontsize
Jun 17, 2026
Jun 13, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The WP-chgFontSize WordPress plugin through 1.8 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-S...Show more
The WP-chgFontSize WordPress plugin through 1.8 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-Site Scripting due to the lack of sanitisation and escapingShow less
1Static Page Extended Project
1Static Page Extended
Jun 17, 2026
Jun 13, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Due to missing checks the Static Page eXtended WordPress plugin through 2.1 is vulnerable to CSRF attacks which allows changing the plugin settings, including required user levels for specific features. This could also l...Show more
Due to missing checks the Static Page eXtended WordPress plugin through 2.1 is vulnerable to CSRF attacks which allows changing the plugin settings, including required user levels for specific features. This could also lead to Stored Cross-Site Scripting due to the lack of escaping in some of the settingsShow less
1Peter's Collaboration E Mails Project
1Peter's Collaboration E Mails
Jun 17, 2026
Jun 13, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The Peter’s Collaboration E-mails WordPress plugin through 2.2.0 is vulnerable to CSRF due to missing nonce checks. This allows the change of its settings, which can be used to lower the required user level, change texts...Show more
The Peter’s Collaboration E-mails WordPress plugin through 2.2.0 is vulnerable to CSRF due to missing nonce checks. This allows the change of its settings, which can be used to lower the required user level, change texts, the used email address and more.Show less
1Rb Internal Links Project
1Rb Internal Links
Jun 17, 2026
Jun 13, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The RB Internal Links WordPress plugin through 2.0.16 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack, as well as perform...Show more
The RB Internal Links WordPress plugin through 2.0.16 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack, as well as perform Stored Cross-Site Scripting attacks due to the lack of sanitisation and escapingShow less
1Genki Pre Publish Reminder Project
1Genki Pre Publish Reminder
Jun 17, 2026
Jun 13, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The Genki Pre-Publish Reminder WordPress plugin through 1.4.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to...Show more
The Genki Pre-Publish Reminder WordPress plugin through 1.4.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored XSS as well as RCE when custom code is added via the plugin settings.Show less
1Useful Banner Manager Project
1Useful Banner Manager
Jun 17, 2026
Jun 13, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The Useful Banner Manager WordPress plugin through 1.6.1 does not perform CSRF checks on POST requests to its admin page, allowing an attacker to trick a logged in admin to add, modify or delete banners from the plugin b...Show more
The Useful Banner Manager WordPress plugin through 1.6.1 does not perform CSRF checks on POST requests to its admin page, allowing an attacker to trick a logged in admin to add, modify or delete banners from the plugin by submitting a form.Show less
1Latest Tweets Widget Project
1Latest Tweets Widget
Jun 17, 2026
Jun 13, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The Latest Tweets Widget WordPress plugin through 1.1.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
1Webriti
1Webriti Smtp Mail
Jun 17, 2026
Jun 13, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The Webriti SMTP Mail WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack