VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,614)

page 282 of 481
  • CVE-2026-11784MedJun 18, 2026
    risk 0.28cvss 4.3epss 0.00

    The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2.6. This is due to missing or incorrect nonce validation on the replace_file…

  • CVE-2024-35648MedJun 17, 2026
    risk 0.28cvss 4.3epss 0.00

    Cross-Site request forgery (CSRF) vulnerability in Andy Moyle Emergency Password Reset allows Cross Site Request Forgery. This issue affects Emergency Password Reset: from n/a through 8.0.

  • CVE-2024-34810MedJun 17, 2026
    risk 0.28cvss 4.3epss 0.00

    Cross-Site request forgery (CSRF) vulnerability in Extend Themes Skyline WP allows Cross Site Request Forgery. This issue affects Skyline WP: from n/a through 1.0.10.

  • CVE-2016-20074MedJun 15, 2026
    risk 0.28cvss 4.3epss 0.00

    WordPress Lazy Content Slider Plugin 3.4 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions by crafting malicious HTML forms. Attackers can trick authenticated administrators into submitting POST requests to the plugin…

  • CVE-2016-20067MedJun 15, 2026
    risk 0.28cvss 4.3epss 0.00

    WordPress CP Polls 1.0.8 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions on behalf of authenticated users. Attackers can craft malicious HTML pages that execute unwanted poll operations when administrators visit the page…

  • CVE-2022-47150MedJun 11, 2026
    risk 0.28cvss 4.3epss 0.00

    Cross-Site request forgery (CSRF) vulnerability in weDevs WooCommerce Conversion Tracking allows Cross Site Request Forgery. This issue affects WooCommerce Conversion Tracking: from n/a through 2.0.10.

  • CVE-2024-32110MedJun 11, 2026
    risk 0.28cvss 4.3epss 0.00

    Cross-Site request forgery (CSRF) vulnerability in Magepeople inc. WpEvently allows Cross Site Request Forgery. This issue affects WpEvently: from n/a through 4.1.2.

  • CVE-2026-53739MedJun 10, 2026
    risk 0.28cvss 4.3epss 0.00

    Yoast Duplicate Post through 4.6 contains a cross-site request forgery vulnerability in the duplicate_post_dismiss_notice handler, which verifies no nonce or capability. Attackers can trick any authenticated user into sending a request that sets the duplicate_post_show_notice…

  • CVE-2026-53736MedJun 10, 2026
    risk 0.28cvss 4.3epss 0.00

    Easy Twitter Feeds before 1.2.13 contains a cross-site request forgery vulnerability in the duplicate_post action handler that lacks nonce verification. Attackers can trick an authenticated user into visiting a crafted link that duplicates any post regardless of post type.

  • CVE-2026-8940MedJun 9, 2026
    risk 0.28cvss 4.3epss 0.00

    The WP Meta Sort Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.9. This is due to missing or incorrect nonce validation on the top-level included script in msp-options.php. This makes it possible for unauthenticated…

  • CVE-2026-8909MedJun 9, 2026
    risk 0.28cvss 4.3epss 0.00

    The WpMobi plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.0.3. This is due to missing or incorrect nonce validation on the handleSaveGeneralSettings function. This makes it possible for unauthenticated attackers to modify…

  • CVE-2026-8904MedJun 9, 2026
    risk 0.28cvss 4.3epss 0.00

    The FastPicker, an order picker and order management system (oms) for WooCommerce on steroids plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.2. This is due to missing or incorrect nonce validation on the settingsPage…

  • CVE-2026-8902MedJun 9, 2026
    risk 0.28cvss 4.3epss 0.00

    The AJAX Report Comments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.4. This is due to missing or incorrect nonce validation on the rc_options_page function. This makes it possible for unauthenticated attackers to…

  • CVE-2026-10553MedJun 9, 2026
    risk 0.28cvss 4.3epss 0.00

    The jQuery Hover Footnotes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4. This is due to missing or incorrect nonce validation on the jqFootnotes_options_subpanel function. This makes it possible for unauthenticated…

  • CVE-2026-11156MedJun 4, 2026
    risk 0.28cvss 4.3epss 0.00

    Inappropriate implementation in CSS in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-11155MedJun 4, 2026
    risk 0.28cvss 4.3epss 0.00

    Inappropriate implementation in CSS in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-9732MedJun 3, 2026
    risk 0.28cvss 4.3epss 0.00

    The EmergencyWP – Dead Man's switch & legacy deliverance plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.2. This is due to missing or incorrect nonce validation on the form_settings_ui (settings save handler,…

  • CVE-2026-9730MedJun 2, 2026
    risk 0.28cvss 4.3epss 0.00

    The Remove NoFollow Commenter URL plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on the gmz_comment_settings_save function. This makes it possible for…

  • CVE-2026-9723MedJun 2, 2026
    risk 0.28cvss 4.3epss 0.00

    The Google Plus One Bottom plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.0.2. This is due to missing or incorrect nonce validation on the googlePlusOneAdmin function. This makes it possible for unauthenticated attackers…

  • CVE-2026-9722MedJun 2, 2026
    risk 0.28cvss 4.3epss 0.00

    The Laiser Tag plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.5. This is due to missing or incorrect nonce validation on the addOptionsPageFields function. This makes it possible for unauthenticated attackers to update…