CWE-352

Medium likelihood

Cross-Site Request Forgery (CSRF)

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

9,302 vulnerabilities with CWE-352
CVE-2025-68885 HIGH
Page Carbajal Custom Post Status <1.1.0 - CSRF
CVSS 7.1
CVE-2025-49354 HIGH
Recent Posts From Each Category <= 1.4 - Cross-Site Request Forgery leading to Stored Cross-Site Scripting
CVSS 7.1
CVE-2025-49353 HIGH
Noindex by Path <= 1.0 - Cross-Site Request Forgery
CVSS 7.1
CVE-2025-49345 HIGH
WP-EasyArchives <= 3.1.2 - Cross-Site Request Forgery
CVSS 7.1
CVE-2025-49344 HIGH
Rene Ade SensitiveTagCloud <1.4.1 - CSRF
CVSS 7.1
CVE-2025-49343 HIGH
Social Profilr <= 1.0 - Cross-Site Request Forgery
CVSS 7.1
CVE-2025-49342 HIGH
Custom Style <= 1.0 - Cross-Site Request Forgery
CVSS 7.1
CVE-2025-59137 HIGH
eLEOPARD Behance Portfolio Manager <1.7.5 - CSRF
CVSS 7.1
CVE-2025-49346 HIGH
Peter Sterling Simple Archive Generator <5.2 - CSRF
CVSS 7.1
CVE-2025-59131 HIGH
Hoernerfranz WP-CalDav2ICS -<1.3.4 - CSRF
CVSS 7.1
CVE-2025-62112 MEDIUM
Merv Barrett Import into Easy Property Listings <2.2.1 - CSRF
CVSS 4.3
CVE-2025-52835 CRITICAL
ConoHa by GMO WING WordPress Migrator - CSRF
CVSS 9.6
CVE-2025-69021 MEDIUM
Ays Pro Popup box <= 6.0.7 - Cross-Site Request Forgery
CVSS 5.4
CVE-2025-68998 MEDIUM
Heateor Social Login <1.1.40 - CSRF
CVSS 5.4
CVE-2025-67013 MEDIUM
Etlsystems D0116s1ula-22454 Firmware - CSRF
CVSS 6.5
CVE-2025-68601 MEDIUM
Rustaurius Five Star Restaurant Reservations <= 2.7.7 - CSRF
CVSS 5.4
CVE-2025-68584 MEDIUM
Vimeotheque <= 2.3.5.2 - Cross-Site Request Forgery
CVSS 4.3
CVE-2025-68583 MEDIUM
Fast User Switching <= 1.4.10 - Cross-Site Request Forgery
CVSS 4.3
CVE-2025-68580 MEDIUM
pluginsware Advanced Classifieds & Directory Pro <=3.2.9 - CSRF
CVSS 4.3
CVE-2025-68573 MEDIUM
Alessandro Piconi Simple Keyword to Link <=1.5 - CSRF
CVSS 5.4
CVE-2025-68567 MEDIUM
wphocus My auctions allegro free edition <= 3.6.32 - CSRF
CVSS 5.4
CVE-2025-68529 MEDIUM
Rhys Wynne WP Email Capture <= 3.12.5 - CSRF
CVSS 4.3
CVE-2025-67625 MEDIUM
Trade Runner <= 3.14 - Cross-Site Request Forgery
CVSS 4.3
CVE-2025-67622 HIGH
titopandub Evergreen Post Tweeter <=1.8.9 - CSRF
CVSS 7.1
CVE-2025-14163 MEDIUM
Premium Addons for Elementor <4.11.53 - CSRF
CVSS 4.3
Details
Vulnerabilities 9,302
Exploit Likelihood Medium