Filtered by CWE-352
Filtered by vendor Subscriptions
Total 8351 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2022-45371 1 Wpmet 1 Shopengine 2025-01-09 5.4 Medium
Cross-Site Request Forgery (CSRF) vulnerability in Wpmet ShopEngine plugin <= 4.1.1 versions.
CVE-2022-45815 1 Stylemixthemes 1 Gdpr Compliance \& Cookie Consent 2025-01-09 4.3 Medium
Cross-Site Request Forgery (CSRF) vulnerability in StylemixThemes GDPR Compliance & Cookie Consent plugin <= 1.2 versions.
CVE-2022-46820 1 Wpjoli 1 Joli Table Of Contents 2025-01-09 5.4 Medium
Cross-Site Request Forgery (CSRF) vulnerability in WPJoli Joli Table Of Contents plugin <= 1.3.9 versions.
CVE-2022-46814 1 Pierros 1 Kodex Posts Likes 2025-01-09 4.3 Medium
Cross-Site Request Forgery (CSRF) vulnerability in Pierre Lebedel Kodex Posts likes plugin <= 2.4.3 versions.
CVE-2022-46856 1 Orion 1 Woocommerce Products Designer 2025-01-09 5.4 Medium
Cross-Site Request Forgery (CSRF) vulnerability in ORION Woocommerce Products Designer plugin <= 4.3.3 versions.
CVE-2022-47144 1 Frenify 1 Mediamatic 2025-01-09 4.3 Medium
Cross-Site Request Forgery (CSRF) vulnerability in Plugincraft Mediamatic – Media Library Folders plugin <= 2.8.1 versions.
CVE-2022-47136 1 Wpmanageninja 1 Ninja Tables 2025-01-09 4.3 Medium
Cross-Site Request Forgery (CSRF) vulnerability in WPManageNinja LLC Ninja Tables – Best Data Table Plugin for WordPress plugin <= 4.3.4 versions.
CVE-2022-47178 1 Simplesharebuttons 1 Simple Share Buttons Adder 2025-01-09 4.3 Medium
Cross-Site Request Forgery (CSRF) vulnerability in Simple Share Buttons Simple Share Buttons Adder plugin <= 8.4.7 versions.
CVE-2022-47174 1 Wordpress 1 Performance Lab 2025-01-09 4.3 Medium
Cross-Site Request Forgery (CSRF) vulnerability in WordPress Performance Team Performance Lab plugin <= 2.2.0 versions.
CVE-2023-23714 1 Uncannyowl 1 Uncanny Toolkit For Learndash 2025-01-09 4.3 Medium
Cross-Site Request Forgery (CSRF) vulnerability in Uncanny Owl Uncanny Toolkit for LearnDash plugin <= 3.6.4.1 versions.
CVE-2023-25971 1 Fixbd 1 Educare 2025-01-09 4.3 Medium
Cross-Site Request Forgery (CSRF) vulnerability in FixBD Educare plugin <= 1.4.1 versions.
CVE-2023-28173 1 Digitalinspiration 1 Google Xml Sitemap For Images 2025-01-09 4.3 Medium
Cross-Site Request Forgery (CSRF) vulnerability in Amit Agarwal Google XML Sitemap for Images plugin <= 2.1.3 versions.
CVE-2023-26514 1 Wpgrim 1 Dynamic Xml Sitemaps Generator For Google 2025-01-09 5.4 Medium
Cross-Site Request Forgery (CSRF) vulnerability in WPGrim Dynamic XML Sitemaps Generator for Google plugin <= 1.3.3 versions.
CVE-2023-26524 1 Expresstech 1 Quiz And Survey Master 2025-01-09 4.3 Medium
Cross-Site Request Forgery (CSRF) vulnerability in ExpressTech Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin <= 8.0.10 versions.
CVE-2023-47230 1 Cimatti 1 Wordpress Contact Forms 2025-01-09 5.4 Medium
Cross-Site Request Forgery (CSRF) vulnerability in Cimatti Consulting WordPress Contact Forms by Cimatti plugin <= 1.6.0 versions.
CVE-2023-33409 1 Minical 1 Minical 2025-01-08 6.5 Medium
Minical 1.0.0 is vulnerable to Cross Site Request Forgery (CSRF) via minical/public/application/controllers/settings/company.php.
CVE-2024-0515 1 Royal-elementor-addons 1 Royal Elementor Addons 2025-01-08 4.3 Medium
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.87. This is due to missing or incorrect nonce validation on the remove_from_compare function. This makes it possible for unauthenticated attackers to remove items from user compare lists via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CVE-2024-0514 1 Royal-elementor-addons 1 Royal Elementor Addons 2025-01-08 4.3 Medium
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.87. This is due to missing or incorrect nonce validation on the add_to_compare function. This makes it possible for unauthenticated attackers to add items to user compare lists via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CVE-2024-0513 1 Royal-elementor-addons 1 Royal Elementor Addons 2025-01-08 4.3 Medium
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.87. This is due to missing or incorrect nonce validation on the remove_from_wishlist function. This makes it possible for unauthenticated attackers to remove items from user wishlists via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CVE-2024-0512 1 Royal-elementor-addons 1 Royal Elementor Addons 2025-01-08 4.3 Medium
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.87. This is due to missing or incorrect nonce validation on the add_to_wishlist function. This makes it possible for unauthenticated attackers to add items to user wishlists via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.