CWE-352

Medium likelihood

Cross-Site Request Forgery (CSRF)

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

9,322 vulnerabilities with CWE-352
CVE-2025-53331 HIGH
samcharrington RSS Digest <= 1.5 - Cross-Site Request Forgery
CVSS 7.1
CVE-2025-53329 HIGH
Społecznościowa 6 PL 2013 <2.0.6 - CSRF
CVSS 7.1
CVE-2025-53327 MEDIUM
Aioseo Multibyte Descriptions <0.0.7 - CSRF
CVSS 4.3
CVE-2025-53317 HIGH
AcmeeDesign WPShapere Lite -n/a-1.4 - XSS
CVSS 7.1
CVE-2025-53315 HIGH
alanft Relocate Upload <0.24.1 - CSRF
CVSS 7.1
CVE-2025-53314 CRITICAL
sh1zen WP Optimizer <2.3.6 - CSRF & SQL Injection
CVSS 9.6
CVE-2025-53313 HIGH
Twitch TV Embed Suite <2.1.0 - CSRF
CVSS 7.1
CVE-2025-53312 HIGH
Looks Awesome OnionBuzz <1.0.8 - CSRF
CVSS 7.1
CVE-2025-53311 HIGH
Navayan Subscribe <= 1.13 - Cross-Site Request Forgery
CVSS 7.1
CVE-2025-53310 HIGH
Funnnny HidePost <= 2.3.8 - Cross-Site Request Forgery
CVSS 7.1
CVE-2025-53308 HIGH
Image Slider With Description <= 9.2 - Cross-Site Request Forgery
CVSS 7.1
CVE-2025-53305 HIGH
WP Forum Server <= 1.8.2 - Cross-Site Request Forgery
CVSS 7.1
CVE-2025-53277 HIGH
Infigo Software IS-theme-companion <= 1.59 - Cross-Site Request Forgery
CVSS 8.8
CVE-2025-53274 HIGH
WP Permalink Translator <1.7.6 - CSRF/XSS
CVSS 7.1
CVE-2025-53273 MEDIUM
Slickstream <= 2.0.3 - Cross-Site Request Forgery
CVSS 4.3
CVE-2025-53272 MEDIUM
opicron Image Cleanup <1.9.2 - CSRF
CVSS 4.3
CVE-2025-53271 HIGH
Anton Bond Additional Order Filters for WooCommerce - Stored XSS
CVSS 7.1
CVE-2025-53270 MEDIUM
Blend Media WordPress CTA <1.6.9 - CSRF
CVSS 4.3
CVE-2025-53269 MEDIUM
My Wp Brand <= 1.1.3 - Cross-Site Request Forgery
CVSS 4.3
CVE-2025-53268 MEDIUM
Import external attachments <= 1.5.12 - Cross-Site Request Forgery
CVSS 4.3
CVE-2025-53267 MEDIUM
Aftab Husain Hide Admin Bar From Front End - CSRF
CVSS 4.3
CVE-2025-53265 MEDIUM
Virusdie < 1.1.3 - Cross-Site Request Forgery
CVSS 5.4
CVE-2025-53264 MEDIUM
ONet Regenerate Thumbnails <1.5 - CSRF
CVSS 4.3
CVE-2025-53263 MEDIUM
Address Autocomplete via Google for Gravity Forms <= 1.3.4 - Cross-Site Request Forgery
CVSS 5.4
CVE-2025-53262 MEDIUM
Writesonic <= 1.0.5 - Cross-Site Request Forgery
CVSS 5.4
Details
Vulnerabilities 9,322
Exploit Likelihood Medium