CWE-352

Medium likelihood

Cross-Site Request Forgery (CSRF)

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

9,349 vulnerabilities with CWE-352
CVE-2023-49164 MEDIUM
OceanWP Ocean Extra <= 2.2.2 - Cross-Site Request Forgery
CVSS 5.4
CVE-2023-49006 MEDIUM
phpsysinfo < 3.4.3 - Cross-Site Request Forgery via XML.php
CVSS 6.5
CVE-2023-48751 MEDIUM
Roland Barker, xnau webdesign Participants Database <2.5.5 - CSRF
CVSS 4.3
CVE-2023-46212 MEDIUM
WP EXtra < 6.2 - Missing Authorization and Cross-Site Request Forgery
CVSS 6.3
CVE-2023-49821 MEDIUM
LiveChat - WP live chat plugin for WordPress <= 4.5.15 - Cross-Site Request Forgery
CVSS 5.4
CVE-2023-49763 MEDIUM
CSprite < 1.1 - Cross-Site Request Forgery
CVSS 4.3
CVE-2023-49761 MEDIUM
Product Enquiry for WooCommerce < 3.0 - Cross-Site Request Forgery
CVSS 5.4
CVE-2023-49760 MEDIUM
WPsoonOnlinePage < 1.9 - Cross-Site Request Forgery
CVSS 5.4
CVE-2023-49759 MEDIUM
WooDiscuz - WooCommerce Comments <= 2.3.0 - Cross-Site Request Forgery
CVSS 5.4
CVE-2023-49163 MEDIUM
teachPress < 9.0.5 - Cross-Site Request Forgery
CVSS 5.4
CVE-2023-49155 MEDIUM
Wow-Company Button Generator <2.3.8 - CSRF
CVSS 4.3
CVE-2023-49153 MEDIUM
Codeastrology Add TO Cart Text Changer And Customize Button, Add Custom Icon < 2.0 - CSRF
CVSS 4.3
CVE-2023-49148 MEDIUM
Kulwant Nagi Affiliate Booster - CSRF
CVSS 5.4
CVE-2023-48781 MEDIUM
MkRapel Regiones y Ciudades de Chile para WC - CSRF
CVSS 4.3
CVE-2023-48778 MEDIUM
VillaTheme Product Size Chart For WooCommerce <1.1.5 - CSRF
CVSS 5.4
CVE-2023-48773 MEDIUM
WP Doctor WooCommerce Login Redirect <2.2.4 - CSRF
CVSS 5.4
CVE-2023-48772 MEDIUM
Arul Prasad J Prevent Landscape Rotation <2.0 - CSRF
CVSS 5.4
CVE-2023-48769 MEDIUM
Blue Coral Chat Bubble < 2.3 - Cross-Site Request Forgery
CVSS 4.3
CVE-2023-48768 MEDIUM
CodeAstrology Team Quantity Plus Minus Button <1.1.9 - CSRF
CVSS 4.3
CVE-2023-5886 HIGH
WordPress Export to XML/CSV <1.4.0 & WP All Export Pro <1.8.6 - CSRF to PHAR Deserialization
CVSS 8.8
CVE-2023-5882 HIGH
Export any WordPress data to XML/CSV < 1.4.0 and WP All Export Pro < 1.8.6 - Cross-Site Request Forgery
CVSS 8.8
CVE-2023-48766 MEDIUM
SVGator - Add Animated SVG Easily <= 1.2.4 - Cross-Site Request Forgery
CVSS 4.3
CVE-2023-48762 MEDIUM
Crocoblock JetElements For Elementor <2.6.13 - CSRF
CVSS 6.3
CVE-2023-46617 MEDIUM
AdFoxly - Ad Manager, AdSense Ads & Ads.Txt <= 1.8.5 - Cross-Site Request Forgery
CVSS 5.4
CVE-2023-48755 MEDIUM
teachPress < 9.0.4 - Cross-Site Request Forgery
CVSS 4.3
Details
Vulnerabilities 9,349
Exploit Likelihood Medium