Vulnerabilities (CVE)

Filtered by CWE-352
Total 7225 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-47609 1 Nicearma 1 Dnui-delete-not-used-image 2023-05-26 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Nicearma DNUI plugin <= 2.8.1 versions.
CVE-2023-25056 1 Slickremix 1 Feed Them Social 2023-05-26 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in SlickRemix Feed Them Social plugin <= 3.0.2 versions.
CVE-2023-23713 1 Theme Tweaker Project 1 Theme Tweaker 2023-05-26 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Manoj Thulasidas Theme Tweaker plugin <= 5.20 versions.
CVE-2023-23705 1 Hmplugin 1 Wordpress Books Gallery 2023-05-26 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in HM Plugin WordPress Books Gallery plugin <= 4.4.8 versions.
CVE-2022-46851 1 Brainstormforce 1 Starter Templates 2023-05-26 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force Starter Templates plugin <= 3.1.20 versions.
CVE-2023-25707 1 Vikwp 1 Vikbooking Hotel Booking Engine \& Pms 2023-05-26 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in E4J s.R.L. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.12 versions.
CVE-2023-25481 1 Podlove 1 Podlove Subscribe Button 2023-05-26 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Podlove Podlove Subscribe button plugin <= 1.3.7 versions.
CVE-2023-25472 1 Podlove 1 Podlove Podcast Publisher 2023-05-26 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Podlove Podlove Podcast Publisher plugin <= 3.8.3 versions.
CVE-2023-23724 1 Winwar 1 Wp Email Capture 2023-05-26 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Winwar Media WP Email Capture plugin <= 3.9.3 versions.
CVE-2023-23706 1 Miniorange 1 Wordpress Social Login And Register \(discord\, Google\, Twitter\, Linkedin\) 2023-05-26 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin <= 7.5.14 versions.
CVE-2014-9414 1 Boldgrid 1 W3 Total Cache 2023-05-26 6.8 MEDIUM N/A
The W3 Total Cache plugin before 0.9.4.1 for WordPress does not properly handle empty nonces, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and hijack the authentication of administrators for requests that change the mobile site redirect URI via the mobile_groups[*][redirect] parameter and an empty _wpnonce parameter in the w3tc_mobile page to wp-admin/admin.php.
CVE-2022-45079 1 Loginizer 1 Loginizer 2023-05-26 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Softaculous Loginizer plugin <= 1.7.5 versions.
CVE-2022-45376 1 Xootix 1 Side Cart Woocommerce 2023-05-26 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in XootiX Side Cart Woocommerce (Ajax) < 2.1 versions.
CVE-2022-47183 1 Stylist Project 1 Stylist 2023-05-26 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in StylistWP Extra Block Design, Style, CSS for ANY Gutenberg Blocks plugin <= 0.2.6 versions.
CVE-2022-41608 1 Asgaros 1 Asgaros Forum 2023-05-26 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Thomas Belser Asgaros Forum plugin <= 2.2.0 versions.
CVE-2022-45076 1 Webmat 1 Flexible Elementor Panel 2023-05-26 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in WebMat Flexible Elementor Panel plugin <= 2.3.8 versions.
CVE-2022-44739 1 Thingsforrestaurants 1 Quick Restaurant Reservations 2023-05-26 N/A 9.8 CRITICAL
Cross-Site Request Forgery (CSRF) vulnerability in ThingsForRestaurants Quick Restaurant Reservations plugin <= 1.5.4 versions.
CVE-2023-23813 1 My Calendar Project 1 My Calendar 2023-05-26 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Joseph C Dolson My Calendar plugin <= 3.4.3 versions.
CVE-2023-23712 1 User-meta 1 User Meta Manager 2023-05-26 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in User Meta Manager plugin <= 3.4.9 versions.
CVE-2023-23680 1 Wp Topbar Project 1 Wp Topbar 2023-05-26 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Bob Goetz WP-TopBar plugin <= 5.36 versions.