Filtered by CWE-352
Total 7170 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2022-45080 1 Krishaweb 1 Add Multiple Marker 2025-01-09 5.4 Medium
Cross-Site Request Forgery (CSRF) vulnerability in KrishaWeb Add Multiple Marker plugin <= 1.2 versions.
CVE-2023-23879 1 Php Execution Project 1 Php Execution 2025-01-09 4.3 Medium
Cross-Site Request Forgery (CSRF) vulnerability in Nicolas Zeh PHP Execution plugin <= 1.0.0 versions.
CVE-2023-22686 1 Trinitronic 1 Nice Paypal Button Lite 2025-01-09 5.4 Medium
Cross-Site Request Forgery (CSRF) vulnerability in TriniTronic Nice PayPal Button Lite plugin <= 1.3.5 versions.
CVE-2023-22691 1 Tipsandtricks-hq 1 Category Specific Rss Feed Subscription 2025-01-09 4.3 Medium
Cross-Site Request Forgery (CSRF) vulnerability in Tips and Tricks HQ, Ruhul Amin Category Specific RSS feed Subscription plugin <= v2.1 versions.
CVE-2023-23790 1 Podsfoundation 1 Pods 2025-01-09 7.1 High
Cross-Site Request Forgery (CSRF) vulnerability in Pods Framework Team Pods – Custom Content Types and Fields plugin <= 2.9.10.2 versions.
CVE-2023-25967 1 Peepso 1 Peepso 2025-01-09 4.3 Medium
Cross-Site Request Forgery (CSRF) vulnerability in PeepSo Community by PeepSo plugin <= 6.0.2.0 versions.
CVE-2022-45846 1 Wpmart 1 Interactive Svg Image Map Builder 2025-01-09 5.4 Medium
Cross-Site Request Forgery (CSRF) vulnerability in Nickys Image Map Pro for WordPress - Interactive SVG Image Map Builder plugin < 5.6.9 versions.
CVE-2024-12605 2025-01-09 4.3 Medium
The AI Scribe – SEO AI Writer, Content Generator, Humanizer, Blog Writer, SEO Optimizer, DALLE-3, AI WordPress Plugin ChatGPT (GPT-4o 128K) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.3. This is due to missing or incorrect nonce validation on the "al_scribe_content_data" actions. This makes it possible for unauthenticated attackers to update plugin settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CVE-2023-27423 1 Mijnpress 1 Auto Prune Posts 2025-01-09 5.4 Medium
Cross-Site Request Forgery (CSRF) vulnerability in Ramon Fincken Auto Prune Posts plugin <= 1.8.0 versions.
CVE-2023-27430 1 Mijnpress 1 Mass Delete Unused Tags 2025-01-09 5.4 Medium
Cross-Site Request Forgery (CSRF) vulnerability in Ramon Fincken Mass Delete Unused Tags plugin <= 2.0.0 versions.
CVE-2023-25698 1 Studiowombat 1 Shoppable Images 2025-01-09 5.4 Medium
Cross-Site Request Forgery (CSRF) vulnerability in Studio Wombat Shoppable Images plugin <= 1.2.3 versions.
CVE-2023-24414 1 Robosoft 1 Robogallery 2025-01-09 4.3 Medium
Cross-Site Request Forgery (CSRF) vulnerability in RoboSoft Photo Gallery, Images, Slider in Rbs Image Gallery plugin <= 3.2.11 versions.
CVE-2023-23890 1 Ljapps 1 Wp Airbnb Review Slider 2025-01-09 7.1 High
Cross-Site Request Forgery (CSRF) vulnerability in LJ Apps WP Airbnb Review Slider plugin <= 3.2 versions.
CVE-2023-32589 1 Pingonline 1 Dyslexiefont Free 2025-01-09 4.3 Medium
Cross-Site Request Forgery (CSRF) vulnerability in PingOnline Dyslexiefont Free plugin <= 1.0.0 versions.
CVE-2022-47134 1 Gallery Metabox Project 1 Gallery Metabox 2025-01-09 4.3 Medium
Cross-Site Request Forgery (CSRF) vulnerability in Bill Erickson Gallery Metabox plugin <= 1.5 versions.
CVE-2023-23813 1 My Calendar Project 1 My Calendar 2025-01-09 5.4 Medium
Cross-Site Request Forgery (CSRF) vulnerability in Joseph C Dolson My Calendar plugin <= 3.4.3 versions.
CVE-2023-23712 1 User-meta 1 User Meta Manager 2025-01-09 5.4 Medium
Cross-Site Request Forgery (CSRF) vulnerability in User Meta Manager plugin <= 3.4.9 versions.
CVE-2023-23680 1 Wp Topbar Project 1 Wp Topbar 2025-01-09 5.4 Medium
Cross-Site Request Forgery (CSRF) vulnerability in Bob Goetz WP-TopBar plugin <= 5.36 versions.
CVE-2023-22688 1 Wp Tabs Slides Project 1 Wp Tabs Slides 2025-01-09 4.3 Medium
Cross-Site Request Forgery (CSRF) vulnerability in Abdul Ibad WP Tabs Slides plugin <= 2.0.3 versions.
CVE-2023-22692 1 Name Directory Project 1 Name Directory 2025-01-09 4.3 Medium
Cross-Site Request Forgery (CSRF) vulnerability in Jeroen Peters Name Directory plugin <= 1.27.1 versions.