Total
8644 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-11641 | 1 Vikwp | 1 Vikbooking Hotel Booking Engine \& Pms | 2025-02-04 | N/A | 8.8 HIGH |
| The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.2. This is due to missing or incorrect nonce validation on the 'save' function. This makes it possible for unauthenticated attackers to change plugin access privileges via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. Successful exploitation allows attackers with subscriber-level privileges and above to upload arbitrary files on the affected site's server which may make remote code execution possible. | |||||
| CVE-2023-1414 | 1 Rextheme | 1 Wp Vr | 2025-02-04 | N/A | 4.3 MEDIUM |
| The WP VR WordPress plugin before 8.3.0 does not have authorisation and CSRF checks in various AJAX actions, one in particular could allow any authenticated users, such as subscriber to update arbitrary tours | |||||
| CVE-2024-1760 | 1 Nsquared | 1 Simply Schedule Appointments | 2025-02-04 | N/A | 4.3 MEDIUM |
| The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6.6.20. This is due to missing or incorrect nonce validation on the ssa_factory_reset() function. This makes it possible for unauthenticated attackers to reset the plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. | |||||
| CVE-2023-26839 | 1 Churchcrm | 1 Churchcrm | 2025-02-04 | N/A | 4.3 MEDIUM |
| A cross-site request forgery (CSRF) vulnerability in ChurchCRM v4.5.3 allows attackers to edit information for existing people on the site. | |||||
| CVE-2024-13510 | 2025-02-04 | N/A | 6.1 MEDIUM | ||
| The ShopSite plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.10. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. | |||||
| CVE-2025-24982 | 2025-02-04 | N/A | 4.3 MEDIUM | ||
| Cross-site request forgery vulnerability exists in Activity Log WinterLock versions prior to 1.2.5. If a user views a malicious page while logged in, the log data may be deleted. | |||||
| CVE-2023-26841 | 1 Churchcrm | 1 Churchcrm | 2025-02-03 | N/A | 6.5 MEDIUM |
| A cross-site request forgery (CSRF) vulnerability in ChurchCRM v4.5.3 allows attackers to change any user's password except for the user that is currently logged in. | |||||
| CVE-2023-26840 | 1 Churchcrm | 1 Churchcrm | 2025-02-03 | N/A | 5.3 MEDIUM |
| A cross-site request forgery (CSRF) vulnerability in ChurchCRM v4.5.3 allows attackers to set a person to a user and set that user to be an Administrator. | |||||
| CVE-2024-13758 | 1 Dwbooster | 1 Cp Contact Form | 2025-01-31 | N/A | 6.5 MEDIUM |
| The CP Contact Form with PayPal plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.52. This is due to missing or incorrect nonce validation on the cp_contact_form_paypal_check_init_actions() function. This makes it possible for unauthenticated attackers to add discount codes via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. | |||||
| CVE-2024-12005 | 1 Infinitescript | 1 Wp-bibtex | 2025-01-31 | N/A | 6.1 MEDIUM |
| The WP-BibTeX plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.1. This is due to missing or incorrect nonce validation on the wp_bibtex_option_page() function. This makes it possible for unauthenticated attackers to inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. | |||||
| CVE-2024-30455 | 1 Gamipress | 1 Gamipress | 2025-01-31 | N/A | 4.3 MEDIUM |
| Cross-Site Request Forgery (CSRF) vulnerability in GamiPress.This issue affects GamiPress: from n/a through 6.8.5. | |||||
| CVE-2023-33359 | 1 Piwigo | 1 Piwigo | 2025-01-31 | N/A | 4.3 MEDIUM |
| Piwigo 13.6.0 is vulnerable to Cross Site Request Forgery (CSRF) in the "add tags" function. | |||||
| CVE-2024-13707 | 1 Ivanm | 1 Wp Image Uploader | 2025-01-31 | N/A | 8.8 HIGH |
| The WP Image Uploader plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is due to missing or incorrect nonce validation on the gky_image_uploader_main_function() function. This makes it possible for unauthenticated attackers to delete arbitrary files via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. | |||||
| CVE-2024-13512 | 1 Wonderjarcreative | 1 Wonder Fontawesome | 2025-01-31 | N/A | 6.1 MEDIUM |
| The Wonder FontAwesome plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.8. This is due to missing or incorrect nonce validation on one of its functions. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. | |||||
| CVE-2024-31932 | 1 Creativethemes | 1 Blocksy Companion | 2025-01-31 | N/A | 5.4 MEDIUM |
| Cross-Site Request Forgery (CSRF) vulnerability in CreativeThemes Blocksy Companion.This issue affects Blocksy Companion: from n/a through 2.0.28. | |||||
| CVE-2025-24749 | 2025-01-31 | N/A | 7.1 HIGH | ||
| Cross-Site Request Forgery (CSRF) vulnerability in Overt Software Solutions LTD EZPZ SAML SP Single Sign On (SSO) allows Cross Site Request Forgery. This issue affects EZPZ SAML SP Single Sign On (SSO): from n/a through 1.2.5. | |||||
| CVE-2023-29815 | 1 Chshcms | 1 Mccms | 2025-01-30 | N/A | 8.8 HIGH |
| mccms v2.6.3 is vulnerable to Cross Site Request Forgery (CSRF). | |||||
| CVE-2024-13720 | 1 Ivanm | 1 Wp Image Uploader | 2025-01-30 | N/A | 8.8 HIGH |
| The WP Image Uploader plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the gky_image_uploader_main_function() function in all versions up to, and including, 1.0.1. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). | |||||
| CVE-2024-13521 | 1 Ilghera | 1 Mailup Auto Subscription | 2025-01-30 | N/A | 6.1 MEDIUM |
| The MailUp Auto Subscription plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.0. This is due to missing or incorrect nonce validation on the mas_options function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. | |||||
| CVE-2020-22334 | 1 Beescms | 1 Beescms | 2025-01-29 | N/A | 6.5 MEDIUM |
| Cross Site Request Forgery (CSRF) vulnerability in beescms v4 allows attackers to delete the administrator account via crafted request to /admin/admin_admin.php. | |||||
