CWE-352

Medium likelihood

Cross-Site Request Forgery (CSRF)

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

9,322 vulnerabilities with CWE-352
CVE-2025-47597 MEDIUM
Maulik Vora WP Podcasts Manager - CSRF
CVSS 4.3
CVE-2025-47596 MEDIUM
Syed Balkhi Beacon Lead Magnets & Lead Capture <1.5.8 - CSRF
CVSS 4.3
CVE-2025-47594 MEDIUM
DAEXT Soccer Live Scores <1.0.5 - CSRF
CVSS 4.3
CVE-2025-47590 MEDIUM
WPSpeed <= 2.6.5 - Cross-Site Request Forgery
CVSS 4.3
CVE-2025-47551 MEDIUM
Wiki Embed <= 1.4.6 - Cross-Site Request Forgery to Settings Change
CVSS 4.3
CVE-2025-47546 HIGH
WP Compress < 6.30.30 - Cross-Site Request Forgery
CVSS 7.1
CVE-2025-47543 MEDIUM
TrueBooker <= 1.0.7 - Cross-Site Request Forgery
CVSS 4.3
CVE-2025-47542 MEDIUM
Simple calendar for Elementor <= 1.6.5 - Cross-Site Request Forgery
CVSS 4.3
CVE-2025-47533 HIGH
Graphina < 3.0.4 - Cross-Site Request Forgery to Local File Inclusion
CVSS 8.1
CVE-2025-47523 MEDIUM
Seznam Webmaster <= 1.4.7 - Cross-Site Request Forgery
CVSS 4.3
CVE-2025-47519 MEDIUM
Scott Paterson Easy PayPal Events <1.2.2 - CSRF
CVSS 4.3
CVE-2025-47517 HIGH
Accept Donations with PayPal & Stripe <= 1.4.5 - Cross-Site Request Forgery to Stored Cross-Site Scripting
CVSS 7.1
CVE-2025-47514 HIGH
Eli ELI's Related Posts Footer Links and Widget <1.2.04.20 - CSRF
CVSS 7.1
CVE-2025-47491 HIGH
A WP Life Contact Form Widget <1.4.6 - CSRF
CVSS 7.4
CVE-2025-47473 MEDIUM
pimwick PW WooCommerce Bulk Edit - CSRF
CVSS 5.4
CVE-2025-47470 MEDIUM
senols GPT3 AI Content Writer <1.9.14 - CSRF
CVSS 4.3
CVE-2025-47468 MEDIUM
Hash Form <= 1.2.8 - Cross-Site Request Forgery
CVSS 4.3
CVE-2025-47466 MEDIUM
Rustaurius Ultimate WP Mail <1.3.4 - CSRF
CVSS 5.4
CVE-2025-47462 HIGH
Ohidul Islam Challan <3.7.58 - CSRF
CVSS 8.8
CVE-2025-47459 MEDIUM
XpeedStudio WP Fundraising Donation & Crowdfunding - CSRF
CVSS 4.3
CVE-2025-47451 MEDIUM
Product Quantity Dropdown For Woocommerce <= 1.2 - Cross-Site Request Forgery
CVSS 4.3
CVE-2025-47448 MEDIUM
ThimPress WP Hotel Booking <2.1.9 - CSRF
CVSS 4.3
CVE-2025-47447 MEDIUM
Hossni Mubarak Cool Author Box <3.0.0 - CSRF
CVSS 4.3
CVE-2025-47446 MEDIUM
Listamester <= 2.3.6 - Cross-Site Request Forgery
CVSS 4.3
CVE-2025-0669 HIGH
BOINC Server < 1.4.3 - Cross-Site Request Forgery
CVSS 8.8
Details
Vulnerabilities 9,322
Exploit Likelihood Medium