Vulnerabilities > Goprayer

DATE CVE VULNERABILITY TITLE RISK
2024-06-14 CVE-2024-4751 Cross-Site Request Forgery (CSRF) vulnerability in Goprayer WP Prayer
The WP Prayer II WordPress plugin through 2.4.7 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
network
low complexity
goprayer CWE-352
4.3
2023-07-12 CVE-2021-4412 Unspecified vulnerability in Goprayer WP Prayer
The WP Prayer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.5.
network
low complexity
goprayer
4.3
2023-04-07 CVE-2023-25705 Cross-site Scripting vulnerability in Goprayer WP Prayer
Auth.
network
low complexity
goprayer CWE-79
4.8
2021-06-01 CVE-2021-24313 Cross-site Scripting vulnerability in Goprayer WP Prayer
The WP Prayer WordPress plugin before 1.6.2 provides the functionality to store requested prayers/praises and list them on a WordPress website.
network
low complexity
goprayer CWE-79
5.4