CWE-352
Cross-Site Request Forgery (CSRF)
Description
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62
CVEs mapped to this weakness (9,580)
page 426 of 479| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-9720 | Med | 0.00 | 4.3 | 0.00 | Jul 29, 2026 | The Facturación Electrónica Costa Rica plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.2. This is due to missing or incorrect nonce validation on the (global scope, included by fvcr_admin_page_html) function. This… | ||
| CVE-2026-14234 | Hig | 0.00 | 7.1 | 0.00 | Jul 29, 2026 | The WOLF WordPress plugin before 1.1.0 does not perform a nonce or capability check on one of its AJAX actions, allowing an unauthenticated attacker to trick a logged-in administrator into writing arbitrary content, including a malicious script, into a post via a cross-site… | ||
| CVE-2026-15136 | Med | 0.00 | 4.3 | 0.00 | Jul 28, 2026 | The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.3.7. This is due to missing or incorrect nonce validation on the process_bulk_action function. This makes it… | ||
| CVE-2026-66474 | Med | 0.00 | 4.3 | 0.00 | Jul 27, 2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Insert Headers and Footers Code – HT Script <= 1.1.8 versions. | ||
| CVE-2026-66428 | Med | 0.00 | 4.3 | 0.00 | Jul 27, 2026 | Unauthenticated Cross Site Request Forgery (CSRF) in WP Google Review Slider <= 18.4 versions. | ||
| CVE-2026-15212 | Hig | 0.00 | 8.8 | 0.00 | Jul 23, 2026 | The WPO365 | Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 43.2. This is due to the Ajax_Service::verify_ajax_request() helper gating its wp_verify_nonce() call behind the boolean option 'enable_nonce_check', which is… | ||
| CVE-2026-65540 | Hig | 0.00 | 7.1 | 0.00 | Jul 23, 2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Popup for CF7 with Sweet Alert <= 1.6.5 versions. | ||
| CVE-2026-65539 | Hig | 0.00 | 7.1 | 0.00 | Jul 23, 2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Kwayy HTML Sitemap <= 4.0 versions. | ||
| CVE-2026-65536 | Med | 0.00 | 6.5 | 0.00 | Jul 23, 2026 | Unauthenticated Cross Site Request Forgery (CSRF) in افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) <= 4.4.5 versions. | ||
| CVE-2026-65488 | Hig | 0.00 | 7.1 | 0.00 | Jul 23, 2026 | Unauthenticated Cross Site Request Forgery (CSRF) in LA-Studio Element Kit for Elementor <= 1.6.2 versions. | ||
| CVE-2026-65471 | Cri | 0.00 | 9.6 | 0.00 | Jul 23, 2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Avada Core <= 5.15.6 versions. | ||
| CVE-2026-65464 | Med | 0.00 | 5.4 | 0.00 | Jul 23, 2026 | Unauthenticated Cross Site Request Forgery (CSRF) in GiveWP <= 4.16.3 versions. | ||
| CVE-2026-65460 | Med | 0.00 | 4.3 | 0.00 | Jul 23, 2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Zarinpal Gateway <= 5.1.0 versions. | ||
| CVE-2026-61981 | Med | 0.00 | 5.4 | 0.00 | Jul 23, 2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Simple Link Directory Pro <= 15.0.8 versions. | ||
| CVE-2026-57785 | Hig | 0.00 | 8.8 | 0.00 | Jul 23, 2026 | Unauthenticated Cross Site Request Forgery (CSRF) in ApusListing <= 1.2.63 versions. | ||
| CVE-2026-57784 | Cri | 0.00 | 9.6 | 0.00 | Jul 23, 2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Ninja Forms File Uploads Extension <= 3.3.26 versions. | ||
| CVE-2026-57626 | Hig | 0.00 | 7.1 | 0.00 | Jul 23, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in MailPoet allows Cross Site Request Forgery. This issue affects MailPoet: from 5.30.0 through 5.33.0. | ||
| CVE-2026-24537 | Med | 0.00 | 4.3 | 0.00 | Jul 23, 2026 | Unauthenticated Cross Site Request Forgery (CSRF) in WP Accessibility Helper (WAH) <= 0.6.6 versions. | ||
| CVE-2026-65757 | Hig | 0.00 | 8.1 | 0.00 | Jul 23, 2026 | Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Modules Anywhere extension - The editor popup could expose restricted module data to authenticated users without the required module permissions or valid request tokens. | ||
| CVE-2026-64876 | Hig | 0.00 | 8.8 | 0.00 | Jul 23, 2026 | Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in GeoIP extension - Database-update requests lacked consistent token and Super User checks, this could cause unauthorized updates. |
- risk 0.00cvss 4.3epss 0.00
The Facturación Electrónica Costa Rica plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.2. This is due to missing or incorrect nonce validation on the (global scope, included by fvcr_admin_page_html) function. This…
- risk 0.00cvss 7.1epss 0.00
The WOLF WordPress plugin before 1.1.0 does not perform a nonce or capability check on one of its AJAX actions, allowing an unauthenticated attacker to trick a logged-in administrator into writing arbitrary content, including a malicious script, into a post via a cross-site…
- risk 0.00cvss 4.3epss 0.00
The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.3.7. This is due to missing or incorrect nonce validation on the process_bulk_action function. This makes it…
- risk 0.00cvss 4.3epss 0.00
Unauthenticated Cross Site Request Forgery (CSRF) in Insert Headers and Footers Code – HT Script <= 1.1.8 versions.
- risk 0.00cvss 4.3epss 0.00
Unauthenticated Cross Site Request Forgery (CSRF) in WP Google Review Slider <= 18.4 versions.
- risk 0.00cvss 8.8epss 0.00
The WPO365 | Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 43.2. This is due to the Ajax_Service::verify_ajax_request() helper gating its wp_verify_nonce() call behind the boolean option 'enable_nonce_check', which is…
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Request Forgery (CSRF) in Popup for CF7 with Sweet Alert <= 1.6.5 versions.
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Request Forgery (CSRF) in Kwayy HTML Sitemap <= 4.0 versions.
- risk 0.00cvss 6.5epss 0.00
Unauthenticated Cross Site Request Forgery (CSRF) in افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) <= 4.4.5 versions.
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Request Forgery (CSRF) in LA-Studio Element Kit for Elementor <= 1.6.2 versions.
- risk 0.00cvss 9.6epss 0.00
Unauthenticated Cross Site Request Forgery (CSRF) in Avada Core <= 5.15.6 versions.
- risk 0.00cvss 5.4epss 0.00
Unauthenticated Cross Site Request Forgery (CSRF) in GiveWP <= 4.16.3 versions.
- risk 0.00cvss 4.3epss 0.00
Unauthenticated Cross Site Request Forgery (CSRF) in Zarinpal Gateway <= 5.1.0 versions.
- risk 0.00cvss 5.4epss 0.00
Unauthenticated Cross Site Request Forgery (CSRF) in Simple Link Directory Pro <= 15.0.8 versions.
- risk 0.00cvss 8.8epss 0.00
Unauthenticated Cross Site Request Forgery (CSRF) in ApusListing <= 1.2.63 versions.
- risk 0.00cvss 9.6epss 0.00
Unauthenticated Cross Site Request Forgery (CSRF) in Ninja Forms File Uploads Extension <= 3.3.26 versions.
- risk 0.00cvss 7.1epss 0.00
Cross-Site Request Forgery (CSRF) vulnerability in MailPoet allows Cross Site Request Forgery. This issue affects MailPoet: from 5.30.0 through 5.33.0.
- risk 0.00cvss 4.3epss 0.00
Unauthenticated Cross Site Request Forgery (CSRF) in WP Accessibility Helper (WAH) <= 0.6.6 versions.
- risk 0.00cvss 8.1epss 0.00
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Modules Anywhere extension - The editor popup could expose restricted module data to authenticated users without the required module permissions or valid request tokens.
- risk 0.00cvss 8.8epss 0.00
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in GeoIP extension - Database-update requests lacked consistent token and Super User checks, this could cause unauthorized updates.