Show filters
1,280 Total Results
Displaying 41-50 of 1,280
Sort by:
Attacker Value
Unknown
CVE-2022-1763
Disclosure Date: June 13, 2022 (last updated February 23, 2025)
Due to missing checks the Static Page eXtended WordPress plugin through 2.1 is vulnerable to CSRF attacks which allows changing the plugin settings, including required user levels for specific features. This could also lead to Stored Cross-Site Scripting due to the lack of escaping in some of the settings
0
Attacker Value
Unknown
CVE-2022-1761
Disclosure Date: June 13, 2022 (last updated February 23, 2025)
The Peter’s Collaboration E-mails WordPress plugin through 2.2.0 is vulnerable to CSRF due to missing nonce checks. This allows the change of its settings, which can be used to lower the required user level, change texts, the used email address and more.
0
Attacker Value
Unknown
CVE-2022-1759
Disclosure Date: June 13, 2022 (last updated February 23, 2025)
The RB Internal Links WordPress plugin through 2.0.16 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack, as well as perform Stored Cross-Site Scripting attacks due to the lack of sanitisation and escaping
0
Attacker Value
Unknown
CVE-2022-1758
Disclosure Date: June 13, 2022 (last updated February 23, 2025)
The Genki Pre-Publish Reminder WordPress plugin through 1.4.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored XSS as well as RCE when custom code is added via the plugin settings.
0
Attacker Value
Unknown
CVE-2022-1694
Disclosure Date: June 13, 2022 (last updated February 23, 2025)
The Useful Banner Manager WordPress plugin through 1.6.1 does not perform CSRF checks on POST requests to its admin page, allowing an attacker to trick a logged in admin to add, modify or delete banners from the plugin by submitting a form.
0
Attacker Value
Unknown
CVE-2022-1624
Disclosure Date: June 13, 2022 (last updated February 23, 2025)
The Latest Tweets Widget WordPress plugin through 1.1.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
0
Attacker Value
Unknown
CVE-2022-1612
Disclosure Date: June 13, 2022 (last updated February 23, 2025)
The Webriti SMTP Mail WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
0
Attacker Value
Unknown
CVE-2022-1608
Disclosure Date: June 13, 2022 (last updated February 23, 2025)
The OnePress Social Locker WordPress plugin through 5.6.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
0
Attacker Value
Unknown
CVE-2022-1605
Disclosure Date: June 13, 2022 (last updated February 23, 2025)
The Email Users WordPress plugin through 4.8.8 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and change the notification settings of arbitrary users
0
Attacker Value
Unknown
CVE-2022-1594
Disclosure Date: June 13, 2022 (last updated February 23, 2025)
The HC Custom WP-Admin URL WordPress plugin through 1.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack, allowing them to change the login URL
0