CWE-352

Medium likelihood

Cross-Site Request Forgery (CSRF)

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

9,321 vulnerabilities with CWE-352
CVE-2025-58956 HIGH
loopus WP Attractive Donations System - CSRF
CVSS 7.1
CVE-2025-58690 HIGH
ptibogxiv Doliconnect <9.5.7 - CSRF
CVSS 7.1
CVE-2025-58688 HIGH
Casengo Live Chat Support <2.1.4 - CSRF
CVSS 7.1
CVE-2025-58687 HIGH
WP CMS Ninja Current Age Plugin <1.7 - CSRF
CVSS 7.1
CVE-2025-58677 HIGH
ShrinkTheWeb (STW) Website Previews <= 2.8.5 - Cross-Site Request Forgery
CVSS 7.1
CVE-2025-58676 HIGH
extendyourweb HORIZONTAL SLIDER -<2.4 - XSS
CVSS 7.1
CVE-2025-58675 MEDIUM
tryinteract Interact: Embed A Quiz On Your Site <3.1 - CSRF
CVSS 4.3
CVE-2025-58670 HIGH
Shankaranand Maurya WP Content Protection - CSRF
CVSS 7.1
CVE-2025-58657 HIGH
EdwardBock Grid <= 2.3.1 - Cross-Site Request Forgery leading to Stored Cross-Site Scripting
CVSS 7.1
CVE-2025-58270 HIGH
NIX Anti-Spam Light <= 0.0.4 - Cross-Site Request Forgery
CVSS 7.1
CVE-2025-58268 HIGH
WPMK PDF Generator <= 1.0.1 - Cross-Site Request Forgery
CVSS 7.1
CVE-2025-58267 HIGH
Aftabul Islam Stock Message <1.1.0 - CSRF
CVSS 7.1
CVE-2025-58262 HIGH
WPDirectoryKit Sweet Energy Efficiency <= 1.0.8 - Cross-Site Request Forgery
CVSS 7.1
CVE-2025-58261 HIGH
Mavis HTTPS to HTTP Redirection <= 1.4.3 - Cross-Site Request Forgery
CVSS 7.1
CVE-2025-58259 HIGH
Nokri <= 1.6.4 - Cross-Site Request Forgery
CVSS 7.1
CVE-2025-58255 CRITICAL
yonisink Custom Post Type Images <0.6 - CSRF
CVSS 9.6
CVE-2025-58250 HIGH
ApusTheme Findgo <= 1.3.55 - Cross-Site Request Forgery
CVSS 8.8
CVE-2025-58244 HIGH
Anps Constructo <= 4.3.9 - Cross-Site Request Forgery
CVSS 8.8
CVE-2025-58236 MEDIUM
Mayo Moriyama Force Update Translations - CSRF
CVSS 4.3
CVE-2025-58224 MEDIUM
Printeers Print & Ship <1.17.0 - CSRF
CVSS 5.4
CVE-2025-58219 MEDIUM
LIJE Show Pages List <= 1.2.0 - Cross-Site Request Forgery
CVSS 4.3
CVE-2025-58200 MEDIUM
Flexible FAQ <= 0.2 - Cross-Site Request Forgery
CVSS 4.3
CVE-2025-58199 MEDIUM
Fastly <= 1.2.28 - Cross-Site Request Forgery
CVSS 4.3
CVE-2025-58032 MEDIUM
Bytes.co WP Compiler <= 1.0.0 - Cross-Site Request Forgery
CVSS 4.3
CVE-2025-58014 MEDIUM
Quiz Maker <= 6.7.0.64 - Cross-Site Request Forgery
CVSS 4.3
Details
Vulnerabilities 9,321
Exploit Likelihood Medium