Filtered by CWE-352
Total 8578 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2023-22678 1 Superior Faq Project 1 Superior Faq 2025-01-10 5.4 Medium
Cross-Site Request Forgery (CSRF) vulnerability in Rafael Dery Superior FAQ plugin <= 1.0.2 versions.
CVE-2023-23721 1 Admin Log Project 1 Admin Log 2025-01-10 4.3 Medium
Cross-Site Request Forgery (CSRF) vulnerability in David Gwyer Admin Log plugin <= 1.50 versions.
CVE-2022-30705 1 Wordpress Ping Optimizer Project 1 Wordpress Ping Optimizer 2025-01-10 5.4 Medium
Cross-Site Request Forgery (CSRF) vulnerability in Pankaj Jha WordPress Ping Optimizer plugin <= 2.35.1.2.3 versions.
CVE-2022-38077 1 Essentialplugin 1 Popup Anything 2025-01-10 4.3 Medium
Cross-Site Request Forgery (CSRF) vulnerability in WP OnlineSupport, Essential Plugin Popup Anything – A Marketing Popup and Lead Generation Conversions plugin <= 2.2.1 versions.
CVE-2023-23861 1 Gmace Project 1 Gmace 2025-01-10 5.4 Medium
Cross-Site Request Forgery (CSRF) vulnerability in German Mesky GMAce plugin <= 1.5.2 versions.
CVE-2022-41633 1 Peepso 1 Peepso 2025-01-10 5.4 Medium
Cross-Site Request Forgery (CSRF) vulnerability in PeepSo Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin <= 6.0.2.0 versions.
CVE-2023-23801 1 Hasthemes 1 Really Simple Google Tag Manager 2025-01-10 4.3 Medium
Cross-Site Request Forgery (CSRF) vulnerability in HasThemes Really Simple Google Tag Manager plugin <= 1.0.6 versions.
CVE-2022-46793 1 Adtribes 1 Product Feed Pro For Woocommerce 2025-01-10 5.4 Medium
Cross-Site Request Forgery (CSRF) vulnerability in AdTribes.Io Product Feed PRO for WooCommerce plugin <= 12.4.4 versions.
CVE-2023-30474 1 Ultimate Noindex Nofollow Tool Ii Project 1 Ultimate Noindex Nofollow Tool Ii 2025-01-10 4.3 Medium
Cross-Site Request Forgery (CSRF) vulnerability in Kilian Evang Ultimate Noindex Nofollow Tool II plugin <= 1.3 versions.
CVE-2024-39628 1 Ninjaforms 1 Ninja Forms 2025-01-09 5.4 Medium
Cross-Site Request Forgery (CSRF) vulnerability in Saturday Drive Ninja Forms allows Cross Site Request Forgery.This issue affects Ninja Forms: from n/a through 3.8.6.
CVE-2022-45074 1 Areteit 1 Activity Reactions For Buddypress 2025-01-09 4.3 Medium
Cross-Site Request Forgery (CSRF) vulnerability in Paramveer Singh for Arete IT Private Limited Activity Reactions For Buddypress plugin <= 1.0.22 versions.
CVE-2022-45080 1 Krishaweb 1 Add Multiple Marker 2025-01-09 5.4 Medium
Cross-Site Request Forgery (CSRF) vulnerability in KrishaWeb Add Multiple Marker plugin <= 1.2 versions.
CVE-2023-23879 1 Php Execution Project 1 Php Execution 2025-01-09 4.3 Medium
Cross-Site Request Forgery (CSRF) vulnerability in Nicolas Zeh PHP Execution plugin <= 1.0.0 versions.
CVE-2023-22686 1 Trinitronic 1 Nice Paypal Button Lite 2025-01-09 5.4 Medium
Cross-Site Request Forgery (CSRF) vulnerability in TriniTronic Nice PayPal Button Lite plugin <= 1.3.5 versions.
CVE-2023-22691 1 Tipsandtricks-hq 1 Category Specific Rss Feed Subscription 2025-01-09 4.3 Medium
Cross-Site Request Forgery (CSRF) vulnerability in Tips and Tricks HQ, Ruhul Amin Category Specific RSS feed Subscription plugin <= v2.1 versions.
CVE-2023-23790 1 Podsfoundation 1 Pods 2025-01-09 7.1 High
Cross-Site Request Forgery (CSRF) vulnerability in Pods Framework Team Pods – Custom Content Types and Fields plugin <= 2.9.10.2 versions.
CVE-2023-25967 1 Peepso 1 Peepso 2025-01-09 4.3 Medium
Cross-Site Request Forgery (CSRF) vulnerability in PeepSo Community by PeepSo plugin <= 6.0.2.0 versions.
CVE-2022-45846 1 Wpmart 1 Interactive Svg Image Map Builder 2025-01-09 5.4 Medium
Cross-Site Request Forgery (CSRF) vulnerability in Nickys Image Map Pro for WordPress - Interactive SVG Image Map Builder plugin < 5.6.9 versions.
CVE-2024-12605 2025-01-09 4.3 Medium
The AI Scribe – SEO AI Writer, Content Generator, Humanizer, Blog Writer, SEO Optimizer, DALLE-3, AI WordPress Plugin ChatGPT (GPT-4o 128K) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.3. This is due to missing or incorrect nonce validation on the "al_scribe_content_data" actions. This makes it possible for unauthenticated attackers to update plugin settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CVE-2023-27423 1 Mijnpress 1 Auto Prune Posts 2025-01-09 5.4 Medium
Cross-Site Request Forgery (CSRF) vulnerability in Ramon Fincken Auto Prune Posts plugin <= 1.8.0 versions.