CWE-352

Medium likelihood

Cross-Site Request Forgery (CSRF)

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

9,347 vulnerabilities with CWE-352
CVE-2024-31303 MEDIUM
Fetch Designs Sign-up Sheets <2.2.11.1 - CSRF
CVSS 4.3
CVE-2024-31301 MEDIUM
Themeisle Multiple Page Generator Plugin - MPG <= 3.4.0 - Cross-Site Request Forgery
CVSS 5.4
CVE-2024-31293 MEDIUM
Easy Digital Downloads < 3.2.6 - Cross-Site Request Forgery
CVSS 4.3
CVE-2024-31289 MEDIUM
Elementor Hello Elementor <3.0.0 - CSRF
CVSS 4.3
CVE-2024-31279 MEDIUM
Catch Plugins Generate Child Theme - CSRF
CVSS 5.4
CVE-2024-31272 MEDIUM
ARForms Form Builder < 1.6.1 - Cross-Site Request Forgery
CVSS 6.3
CVE-2024-31271 MEDIUM
Supsystic Ultimate Maps <1.2.16 - CSRF
CVSS 4.3
CVE-2024-31269 MEDIUM
Supsystic Easy Google Maps <= 1.11.11 - Cross-Site Request Forgery
CVSS 4.3
CVE-2024-31268 MEDIUM
AppPresser < 4.3.0 - Cross-Site Request Forgery
CVSS 4.3
CVE-2024-31265 LOW
SumoMe Sumo < 1.34 - Cross-Site Request Forgery
CVSS 3.7
CVE-2024-31264 MEDIUM
Post Views Counter <= 1.4.4 - Unauthenticated Cross-Site Request Forgery
CVSS 4.3
CVE-2024-31263 MEDIUM
aerin Loan Repayment Calculator & App - CSRF
CVSS 5.4
CVE-2024-31262 MEDIUM
Jcodex WooCommerce Checkout Field Editor <2.1.8 - CSRF
CVSS 5.4
CVE-2024-31251 MEDIUM
Community by PeepSo < 6.3.1.1 - Cross-Site Request Forgery
CVSS 4.3
CVE-2024-31250 MEDIUM
WP Server Health Stats <1.7.3 - CSRF
CVSS 4.3
CVE-2024-31239 MEDIUM
Nudgify Social Proof, Sales Popup & FOMO <= 1.3.3 - Cross-Site Request Forgery
CVSS 4.3
CVE-2024-31238 MEDIUM
Smart Online Order for Clover <= 1.5.5 - Cross-Site Request Forgery Leading to Coupon Creation/Modification
CVSS 5.4
CVE-2024-31235 MEDIUM
WebToffee WordPress Comments Import & Export <2.3.5 - CSRF
CVSS 4.3
CVE-2024-31372 MEDIUM
Arnan de Gans No-Bot Registration <1.9.1 - CSRF
CVSS 4.3
CVE-2024-31371 MEDIUM
Xylus Themes WP Event Aggregator <= 1.7.6 - Cross-Site Request Forgery
CVSS 4.3
CVE-2024-22721 MEDIUM
Form Tools 3.1.1 - Cross-Site Request Forgery
CVSS 6.3
CVE-2024-32105 MEDIUM
ELEXtensions ELEX WooCommerce Dynamic Pricing and Discounts <2.1.2 ...
CVSS 4.3
CVE-2024-32109 MEDIUM
WP Matterport Shortcode <2.1.9 - CSRF
CVSS 4.3
CVE-2024-32108 MEDIUM
Stephanie Leary Convert Post Types <1.4 - CSRF
CVSS 4.3
CVE-2024-32107 MEDIUM
XLPlugins Finale Lite < 2.18.0 - Cross-Site Request Forgery
CVSS 4.3
Details
Vulnerabilities 9,347
Exploit Likelihood Medium