Vulnerabilities > Cross-Site Request Forgery (CSRF)

DATE CVE VULNERABILITY TITLE RISK
2023-03-14 CVE-2022-47163 Cross-Site Request Forgery (CSRF) vulnerability in WP CSV to Database Project WP CSV to Database
Cross-Site Request Forgery (CSRF) vulnerability in Tips and Tricks HQ, josh401 WP CSV to Database – Insert CSV file content into WordPress plugin <= 2.6 versions.
network
high complexity
wp-csv-to-database-project CWE-352
7.5
2023-03-13 CVE-2023-25973 Cross-Site Request Forgery (CSRF) vulnerability in Flamescorpion Auto Affiliate Links
Cross-Site Request Forgery (CSRF) vulnerability in Lucian Apostol Auto Affiliate Links plugin <= 6.3.0.2 versions.
network
low complexity
flamescorpion CWE-352
8.8
2023-03-10 CVE-2023-1205 Cross-Site Request Forgery (CSRF) vulnerability in Netgear Rax30 Firmware
NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 is vulnerable to cross-site request forgery attacks on all endpoints due to improperly implemented CSRF protections.
network
low complexity
netgear CWE-352
8.8
2023-03-01 CVE-2022-48309 Cross-Site Request Forgery (CSRF) vulnerability in Sophos Connect
A CSRF vulnerability allows malicious websites to retrieve logs and technical support archives in Sophos Connect versions older than 2.2.90.
network
low complexity
sophos CWE-352
4.3
2023-03-01 CVE-2022-46798 Cross-Site Request Forgery (CSRF) vulnerability in Hasthemes Woolentor - Woocommerce Elementor Addons + Builder
Cross-Site Request Forgery (CSRF) vulnerability in HasThemes ShopLentor plugin <= 2.5.1 leading to plugin settings change.
network
low complexity
hasthemes CWE-352
5.4
2023-03-01 CVE-2022-46805 Cross-Site Request Forgery (CSRF) vulnerability in Wptrio Conditional Shipping for Woocommerce
Cross-Site Request Forgery (CSRF) vulnerability in Lauri Karisola / WP Trio Conditional Shipping for WooCommerce plugin <= 2.3.1 leading to activation/deactivation of plugin rulesets.
network
low complexity
wptrio CWE-352
5.4
2023-03-01 CVE-2022-46806 Cross-Site Request Forgery (CSRF) vulnerability in Villatheme Cart ALL in ONE for Woocommerce
Cross-Site Request Forgery (CSRF) vulnerability in VillaTheme Cart All In One For WooCommerce plugin <= 1.1.10 leading to cart modification.
network
low complexity
villatheme CWE-352
4.3
2023-03-01 CVE-2022-47148 Cross-Site Request Forgery (CSRF) vulnerability in Wpovernight Woocommerce PDF Invoices& Packing Slips
Cross-Site Request Forgery (CSRF) vulnerability in WP Overnight PDF Invoices & Packing Slips for WooCommerce plugin <= 3.2.5 leading to popup dismiss.
network
low complexity
wpovernight CWE-352
4.3
2023-03-01 CVE-2022-38468 Cross-Site Request Forgery (CSRF) vulnerability in Imagely Nextgen Gallery
Cross-Site Request Forgery (CSRF) vulnerability in Imagely WordPress Gallery Plugin – NextGEN Gallery plugin <= 3.28 leading to thumbnail alteration.
network
low complexity
imagely CWE-352
4.3
2023-03-01 CVE-2022-40198 Cross-Site Request Forgery (CSRF) vulnerability in Standalonetech Terawallet
Cross-Site Request Forgery (CSRF) vulnerability in StandaloneTech TeraWallet – For WooCommerce plugin <= 1.3.24 leading to plugin settings change.
network
low complexity
standalonetech CWE-352
4.3