Vulnerabilities > Cross-Site Request Forgery (CSRF)

DATE CVE VULNERABILITY TITLE RISK
2019-08-16 CVE-2019-15115 Cross-Site Request Forgery (CSRF) vulnerability in Profilepress Loginwp
The peters-login-redirect plugin before 2.9.2 for WordPress has CSRF.
network
low complexity
profilepress CWE-352
8.8
2019-08-16 CVE-2019-15114 Cross-Site Request Forgery (CSRF) vulnerability in Ncrafts Formcraft
The formcraft-form-builder plugin before 1.2.2 for WordPress has CSRF.
network
low complexity
ncrafts CWE-352
8.8
2019-08-16 CVE-2019-15113 Cross-Site Request Forgery (CSRF) vulnerability in Codeermeneer Companion Sitemap Generator
The companion-sitemap-generator plugin before 3.7.0 for WordPress has CSRF.
network
low complexity
codeermeneer CWE-352
8.8
2019-08-16 CVE-2018-20974 Cross-Site Request Forgery (CSRF) vulnerability in Joomsky JS JOB Manager
The js-jobs plugin before 1.0.7 for WordPress has CSRF.
network
low complexity
joomsky CWE-352
8.8
2019-08-16 CVE-2018-20972 Cross-Site Request Forgery (CSRF) vulnerability in Codeermeneer Companion Auto Update
The companion-auto-update plugin before 3.2.1 for WordPress has CSRF.
network
low complexity
codeermeneer CWE-352
8.8
2019-08-16 CVE-2018-20971 Cross-Site Request Forgery (CSRF) vulnerability in Churchadminplugin Church Admin
The church-admin plugin before 1.2550 for WordPress has CSRF affecting the upload of a bible reading plan.
network
low complexity
churchadminplugin CWE-352
8.8
2019-08-16 CVE-2017-18547 Cross-Site Request Forgery (CSRF) vulnerability in Neliosoftware Nelio AB Testing
The nelio-ab-testing plugin before 4.6.4 for WordPress has CSRF in experiment forms.
network
low complexity
neliosoftware CWE-352
8.8
2019-08-16 CVE-2017-18546 Cross-Site Request Forgery (CSRF) vulnerability in Jayj Quicktag Project Jayj Quicktag
The jayj-quicktag plugin before 1.3.2 for WordPress has CSRF.
network
low complexity
jayj-quicktag-project CWE-352
8.8
2019-08-16 CVE-2017-18544 Cross-Site Request Forgery (CSRF) vulnerability in Invite Anyone Project Invite Anyone
The invite-anyone plugin before 1.3.16 for WordPress has admin-panel CSRF.
network
low complexity
invite-anyone-project CWE-352
8.8
2019-08-16 CVE-2015-9322 Cross-Site Request Forgery (CSRF) vulnerability in Erident Custom Login and Dashboard Project Erident Custom Login and Dashboard
The erident-custom-login-and-dashboard plugin before 3.5 for WordPress has CSRF.
8.8