CWE-352
9,673 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium
Cross-Site Request Forgery (CSRF)
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
CVEs (9,673)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Toolbar To Share Project 1Toolbar To Share Jun 17, 2026 Jun 13, 2022 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The ToolBar to Share plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0. This is due to missing nonce validation on the plugin_toolbar_comparte page. This makes it poss...Show more |
The Copify plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.0. This is due to missing nonce validation on the CopifySettings page. This makes it possible for unauthen...Show more |
1Private Files Project 1Private Files Jun 17, 2026 Jun 13, 2022 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 The Private Files WordPress plugin through 0.40 is missing CSRF check when disabling the protection, which could allow attackers to make a logged in admin perform such action via a CSRF attack and make the blog public |
1Quick Subscribe Project 1Quick Subscribe Jun 17, 2026 Jun 13, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The Quick Subscribe WordPress plugin through 1.7.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and leading to Stored X...Show more |
1One Click Plugin Updater Project 1One Click Plugin Updater Jun 17, 2026 Jun 13, 2022 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 The One Click Plugin Updater WordPress plugin through 2.4.14 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and disable /...Show more |
1New User Email Set Up Project 1New User Email Set Up Jun 17, 2026 Jun 13, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The New User Email Set Up WordPress plugin through 0.5.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack |
1Change Uploaded File Permissions Project 1Change Uploaded File Permissions Jun 17, 2026 Jun 13, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Due to missing checks the Change Uploaded File Permissions WordPress plugin through 4.0.0 is vulnerable to CSRF attacks. This can be used to change the file and folder permissions of any folder. This could be problematic...Show more |
The Sideblog WordPress plugin through 6.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-Site Sc...Show more |
The postTabs WordPress plugin through 2.10.6 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack, which also lead to Stored Cr...Show more |
The LaTeX for WordPress plugin through 3.4.10 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack which could also lead to Sto...Show more |
1Auto Delete Posts Project 1Auto Delete Posts Jun 17, 2026 Jun 13, 2022 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 The Auto Delete Posts WordPress plugin through 1.3.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and delete specific p...Show more |
1Hot Linked Image Cacher Project 1Hot Linked Image Cacher Jun 17, 2026 Jun 13, 2022 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The Hot Linked Image Cacher WordPress plugin through 1.16 is vulnerable to CSRF. This can be used to store / cache images from external domains on the server, which could lead to legal risks (due to copyright violations...Show more |
1Wp Chgfontsize Project 1Wp Chgfontsize Jun 17, 2026 Jun 13, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The WP-chgFontSize WordPress plugin through 1.8 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-S...Show more |
1Static Page Extended Project 1Static Page Extended Jun 17, 2026 Jun 13, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Due to missing checks the Static Page eXtended WordPress plugin through 2.1 is vulnerable to CSRF attacks which allows changing the plugin settings, including required user levels for specific features. This could also l...Show more |
1Peter's Collaboration E Mails Project 1Peter's Collaboration E Mails Jun 17, 2026 Jun 13, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The Peter’s Collaboration E-mails WordPress plugin through 2.2.0 is vulnerable to CSRF due to missing nonce checks. This allows the change of its settings, which can be used to lower the required user level, change texts...Show more |
1Rb Internal Links Project 1Rb Internal Links Jun 17, 2026 Jun 13, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The RB Internal Links WordPress plugin through 2.0.16 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack, as well as perform...Show more |
1Genki Pre Publish Reminder Project 1Genki Pre Publish Reminder Jun 17, 2026 Jun 13, 2022 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The Genki Pre-Publish Reminder WordPress plugin through 1.4.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to...Show more |
1Useful Banner Manager Project 1Useful Banner Manager Jun 17, 2026 Jun 13, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The Useful Banner Manager WordPress plugin through 1.6.1 does not perform CSRF checks on POST requests to its admin page, allowing an attacker to trick a logged in admin to add, modify or delete banners from the plugin b...Show more |
1Latest Tweets Widget Project 1Latest Tweets Widget Jun 17, 2026 Jun 13, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The Latest Tweets Widget WordPress plugin through 1.1.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack |
The Webriti SMTP Mail WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack |