VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,607)

page 379 of 481
  • CVE-2022-29489MedSep 16, 2022
    risk 0.28cvss 4.3epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Sucuri Security plugin <= 1.8.33 at WordPress leading to Event log entry creation.

  • CVE-2022-38329MedSep 13, 2022
    risk 0.28cvss 4.3epss 0.00

    A CSRF vulnerability in Shopxian CMS 3.0.0 could allow an unauthenticated, remote attacker to craft a malicious link, potentially causing the administrator to perform unintended actions on an affected system. The vulnerability could allow attackers to modify or delete specific…

  • CVE-2022-37405MedSep 9, 2022
    risk 0.28cvss 4.3epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Mickey Kay's Better Font Awesome plugin <= 2.0.1 at WordPress.

  • CVE-2022-3121MedSep 5, 2022
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in SourceCodester Online Employee Leave Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/addemployee.php. The manipulation leads to cross-site request forgery. The…

  • CVE-2022-2657MedSep 5, 2022
    risk 0.28cvss 4.3epss 0.00

    The Multivendor Marketplace Solution for WooCommerce WordPress plugin before 3.8.12 is lacking authorisation and CSRF in multiple AJAX actions, which could allow any authenticated users, such as subscriber to call them and suspend vendors (reporter by the submitter) or update…

  • CVE-2018-14519MedAug 24, 2022
    risk 0.28cvss 4.3epss 0.00

    An issue was discovered in Kirby 2.5.12. The delete page functionality suffers from a CSRF flaw. A remote attacker can craft a malicious CSRF page and force the user to delete a page.

  • CVE-2022-36389MedAug 23, 2022
    risk 0.28cvss 4.3epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in WordPlus Better Messages plugin <= 1.9.9.148 at WordPress.

  • CVE-2022-36346MedAug 22, 2022
    risk 0.28cvss 4.3epss 0.00

    Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Max Foundry MaxButtons plugin <= 9.2 at WordPress.

  • CVE-2022-2389MedAug 22, 2022
    risk 0.28cvss 4.3epss 0.00

    The Abandoned Cart Recovery for WooCommerce, Follow Up Emails, Newsletter Builder & Marketing Automation By Autonami WordPress plugin before 2.1.2 does not have authorisation and CSRF checks in one of its AJAX action, allowing any authenticated users, such as subscriber to…

  • CVE-2022-2382MedAug 22, 2022
    risk 0.28cvss 4.3epss 0.00

    The Product Slider for WooCommerce WordPress plugin before 2.5.7 has flawed CSRF checks and lack authorisation in some of its AJAX actions, allowing any authenticated users, such as subscriber to call them. One in particular could allow them to delete arbitrary blog options.

  • CVE-2022-2276MedAug 22, 2022
    risk 0.28cvss 4.3epss 0.00

    The WP Edit Menu WordPress plugin before 1.5.0 does not have authorisation and CSRF in an AJAX action, which could allow unauthenticated attackers to delete arbitrary posts/pages from the blog

  • CVE-2022-2275MedAug 22, 2022
    risk 0.28cvss 4.3epss 0.00

    The WP Edit Menu WordPress plugin before 1.5.0 does not have CSRF in an AJAX action, which could allow attackers to make a logged in admin delete arbitrary posts/pages from the blog via a CSRF attack

  • CVE-2022-2172MedAug 22, 2022
    risk 0.28cvss 4.3epss 0.00

    The LinkWorth WordPress plugin before 3.3.4 does not implement nonce checks, which could allow attackers to make a logged in admin change settings via a CSRF attack.

  • CVE-2022-1251MedAug 22, 2022
    risk 0.28cvss 4.3epss 0.00

    The Ask me WordPress theme before 6.8.4 does not perform nonce checks when processing POST requests to the Edit Profile page, allowing an attacker to trick a user to change their profile information by sending a crafted request.

  • CVE-2021-36852MedAug 22, 2022
    risk 0.28cvss 4.3epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in ThimPress WP Hotel Booking plugin <= 1.10.5 at WordPress.

  • CVE-2022-36968MedAug 2, 2022
    risk 0.28cvss 4.3epss 0.00

    In Progress WS_FTP Server prior to version 8.7.3, forms within the administrative interface did not include a nonce to mitigate the risk of cross-site request forgery (CSRF) attacks.

  • CVE-2022-2144MedJul 17, 2022
    risk 0.28cvss 4.3epss 0.00

    The Jquery Validation For Contact Form 7 WordPress plugin before 5.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change Blog options like default_role, users_can_register via a CSRF attack

  • CVE-2022-2123MedJul 11, 2022
    risk 0.28cvss 4.3epss 0.00

    The WP Opt-in WordPress plugin through 1.4.1 is vulnerable to CSRF which allows changed plugin settings and can be used for sending spam emails.

  • CVE-2022-1957MedJul 11, 2022
    risk 0.28cvss 4.3epss 0.00

    The Comment License WordPress plugin before 1.4.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

  • CVE-2022-1956MedJul 11, 2022
    risk 0.28cvss 4.3epss 0.00

    The Shortcut Macros WordPress plugin through 1.3 does not have authorisation and CSRF checks in place when updating its settings, which could allow any authenticated users, such as subscriber, to update them.