Vulnerabilities > Cross-Site Request Forgery (CSRF)

DATE CVE VULNERABILITY TITLE RISK
2022-11-18 CVE-2022-45073 Cross-Site Request Forgery (CSRF) vulnerability in Miniorange Wordpress Rest API Authentication
Cross-Site Request Forgery (CSRF) vulnerability in REST API Authentication plugin <= 2.4.0 on WordPress.
network
low complexity
miniorange CWE-352
8.8
2022-11-18 CVE-2022-38075 Cross-Site Request Forgery (CSRF) vulnerability in Webartesanal Mantenimiento web
Cross-Site Request Forgery (CSRF) vulnerability leading to Stored Cross-Site Scripting (XSS) in Mantenimiento web plugin <= 0.13 on WordPress.
network
low complexity
webartesanal CWE-352
6.1
2022-11-18 CVE-2022-40686 Cross-Site Request Forgery (CSRF) vulnerability in Constantcontact Creative Mail
Cross-Site Request Forgery (CSRF) vulnerability in Creative Mail plugin <= 1.5.4 on WordPress.
network
low complexity
constantcontact CWE-352
8.8
2022-11-18 CVE-2022-40687 Cross-Site Request Forgery (CSRF) vulnerability in Constantcontact Creative Mail
Cross-Site Request Forgery (CSRF) vulnerability in Creative Mail plugin <= 1.5.4 on WordPress.
network
low complexity
constantcontact CWE-352
8.8
2022-11-18 CVE-2022-41805 Cross-Site Request Forgery (CSRF) vulnerability in Booster for Woocommerce
Cross-Site Request Forgery (CSRF) vulnerability in Booster for WooCommerce plugin <= 5.6.6 on WordPress.
network
low complexity
booster CWE-352
4.3
2022-11-17 CVE-2022-40192 Cross-Site Request Forgery (CSRF) vulnerability in Gvectors Wpforo Forum
Cross-Site Request Forgery (CSRF) vulnerability in wpForo Forum plugin <= 2.0.9 on WordPress.
network
low complexity
gvectors CWE-352
8.8
2022-11-17 CVE-2022-45071 Cross-Site Request Forgery (CSRF) vulnerability in Wpml
Cross-Site Request Forgery (CSRF) vulnerability in WPML Multilingual CMS premium plugin <= 4.5.13 on WordPress.
network
low complexity
wpml CWE-352
8.8
2022-11-17 CVE-2022-45072 Cross-Site Request Forgery (CSRF) vulnerability in Wpml
Cross-Site Request Forgery (CSRF) vulnerability in WPML Multilingual CMS premium plugin <= 4.5.13 on WordPress.
network
low complexity
wpml CWE-352
4.3
2022-11-17 CVE-2022-42246 Cross-Site Request Forgery (CSRF) vulnerability in Duofoxtechnologies Duofox CMS 0.0.4
Doufox 0.0.4 contains a CSRF vulnerability that can add system administrator account.
network
low complexity
duofoxtechnologies CWE-352
8.8
2022-11-16 CVE-2022-4021 Cross-Site Request Forgery (CSRF) vulnerability in Permalink Manager Lite Project Permalink Manager Lite
The Permalink Manager Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.2.20.1.
network
low complexity
permalink-manager-lite-project CWE-352
4.3