VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,580)

page 383 of 479
  • CVE-2021-24749MedNov 29, 2021
    risk 0.28cvss 4.3epss 0.00

    The URL Shortify WordPress plugin before 1.5.1 does not have CSRF check in place when bulk-deleting links or groups, which could allow attackers to make a logged in admin delete arbitrary link and group via a CSRF attack.

  • CVE-2021-24668MedNov 23, 2021
    risk 0.28cvss 4.3epss 0.00

    The MAZ Loader WordPress plugin before 1.4.1 does not enforce nonce checks, which allows attackers to make administrators delete arbitrary loaders via a CSRF attack

  • CVE-2021-24853MedNov 17, 2021
    risk 0.28cvss 4.3epss 0.00

    The QR Redirector WordPress plugin before 1.6 does not have capability and CSRF checks when saving bulk QR Redirector settings via the qr_save_bulk AJAX action, which could allow any authenticated user, such as subscriber to change the redirect response status code of arbitrary…

  • CVE-2021-24776MedNov 17, 2021
    risk 0.28cvss 4.3epss 0.00

    The WP Performance Score Booster WordPress plugin before 2.1 does not have CSRF check when saving its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.

  • CVE-2021-3776MedNov 13, 2021
    risk 0.28cvss 5.4epss 0.00

    showdoc is vulnerable to Cross-Site Request Forgery (CSRF)

  • CVE-2021-3775MedNov 13, 2021
    risk 0.28cvss 5.4epss 0.00

    showdoc is vulnerable to Cross-Site Request Forgery (CSRF)

  • CVE-2021-24832MedNov 8, 2021
    risk 0.28cvss 4.3epss 0.00

    The WP SEO Redirect 301 WordPress plugin before 2.3.2 does not have CSRF in place when deleting redirects, which could allow attackers to make a logged in admin delete them via a CSRF attack

  • CVE-2021-24806MedNov 8, 2021
    risk 0.28cvss 4.3epss 0.00

    The wpDiscuz WordPress plugin before 7.3.4 does check for CSRF when adding, editing and deleting comments, which could allow attacker to make logged in users such as admin edit and delete arbitrary comment, or the user who made the comment to edit it via a CSRF attack. Attackers…

  • CVE-2021-24801MedNov 8, 2021
    risk 0.28cvss 4.3epss 0.00

    The WP Survey Plus WordPress plugin through 1.0 does not have any authorisation and CSRF checks in place in its AJAX actions, allowing any user to call them and add/edit/delete Surveys. Furthermore, due to the lack of sanitization in the Surveys' Title, this could also lead to…

  • CVE-2021-24799MedNov 1, 2021
    risk 0.28cvss 4.3epss 0.00

    The Far Future Expiry Header WordPress plugin before 1.5 does not have CSRF check when saving its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.

  • CVE-2021-24572MedNov 1, 2021
    risk 0.28cvss 4.3epss 0.00

    The Accept Donations with PayPal WordPress plugin before 1.3.1 provides a function to create donation buttons which are internally stored as posts. The deletion of a button is not CSRF protected and there is no control to check if the deleted post was a button post. As a result,…

  • CVE-2021-24570MedNov 1, 2021
    risk 0.28cvss 4.3epss 0.00

    The Accept Donations with PayPal WordPress plugin before 1.3.1 offers a function to create donation buttons, which internally are posts. The process to create a new button is lacking a CSRF check. An attacker could use this to make an authenticated admin create a new button.…

  • CVE-2015-10001MedNov 1, 2021
    risk 0.28cvss 4.3epss 0.00

    The WP-Stats WordPress plugin before 2.52 does not have CSRF check when saving its settings, and did not escape some of them when outputting them, allowing attacker to make logged in high privilege users change them and set Cross-Site Scripting payloads

  • CVE-2021-34743MedOct 21, 2021
    risk 0.28cvss 4.3epss 0.00

    A vulnerability in the application integration feature of Cisco Webex Software could allow an unauthenticated, remote attacker to authorize an external application to integrate with and access a user's account without that user's express consent. This vulnerability is due to…

  • CVE-2021-36877MedSep 27, 2021
    risk 0.28cvss 4.3epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in WordPress uListing plugin (versions <= 2.0.5) makes it possible for attackers to modify user roles.

  • CVE-2021-36878MedSep 27, 2021
    risk 0.28cvss 4.3epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in WordPress uListing plugin (versions <= 2.0.5) makes it possible for attackers to update settings.

  • CVE-2021-24583MedSep 20, 2021
    risk 0.28cvss 4.3epss 0.02

    The Timetable and Event Schedule WordPress plugin before 2.4.2 does not have proper access control when deleting a timeslot, allowing any user with the edit_posts capability (contributor+) to delete arbitrary timeslot from any events. Furthermore, no CSRF check is in place as…

  • CVE-2020-21321MedSep 15, 2021
    risk 0.28cvss 4.3epss 0.01

    emlog v6.0 contains a Cross-Site Request Forgery (CSRF) via /admin/link.php?action=addlink, which allows attackers to arbitrarily add articles.

  • CVE-2021-39124MedSep 14, 2021
    risk 0.28cvss 4.3epss 0.01

    The Cross-Site Request Forgery (CSRF) failure retry feature of Atlassian Jira Server and Data Center before version 8.16.0 allows remote attackers who are able to trick a user into retrying a request to bypass CSRF protection and replay a crafted request.

  • CVE-2021-24725MedSep 13, 2021
    risk 0.28cvss 4.3epss 0.00

    The Comment Link Remove and Other Comment Tools WordPress plugin before 2.1.6 does not have CSRF check in its 'Delete comments easily', which could allow attackers to make logged in admin delete arbitrary comments