Show filters
1,280 Total Results
Displaying 41-50 of 1,280
Sort by:
Attacker Value
Unknown

CVE-2022-1763

Disclosure Date: June 13, 2022 (last updated February 23, 2025)
Due to missing checks the Static Page eXtended WordPress plugin through 2.1 is vulnerable to CSRF attacks which allows changing the plugin settings, including required user levels for specific features. This could also lead to Stored Cross-Site Scripting due to the lack of escaping in some of the settings
Attacker Value
Unknown

CVE-2022-1761

Disclosure Date: June 13, 2022 (last updated February 23, 2025)
The Peter’s Collaboration E-mails WordPress plugin through 2.2.0 is vulnerable to CSRF due to missing nonce checks. This allows the change of its settings, which can be used to lower the required user level, change texts, the used email address and more.
Attacker Value
Unknown

CVE-2022-1759

Disclosure Date: June 13, 2022 (last updated February 23, 2025)
The RB Internal Links WordPress plugin through 2.0.16 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack, as well as perform Stored Cross-Site Scripting attacks due to the lack of sanitisation and escaping
Attacker Value
Unknown

CVE-2022-1758

Disclosure Date: June 13, 2022 (last updated February 23, 2025)
The Genki Pre-Publish Reminder WordPress plugin through 1.4.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored XSS as well as RCE when custom code is added via the plugin settings.
Attacker Value
Unknown

CVE-2022-1694

Disclosure Date: June 13, 2022 (last updated February 23, 2025)
The Useful Banner Manager WordPress plugin through 1.6.1 does not perform CSRF checks on POST requests to its admin page, allowing an attacker to trick a logged in admin to add, modify or delete banners from the plugin by submitting a form.
Attacker Value
Unknown

CVE-2022-1624

Disclosure Date: June 13, 2022 (last updated February 23, 2025)
The Latest Tweets Widget WordPress plugin through 1.1.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
Attacker Value
Unknown

CVE-2022-1612

Disclosure Date: June 13, 2022 (last updated February 23, 2025)
The Webriti SMTP Mail WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
Attacker Value
Unknown

CVE-2022-1608

Disclosure Date: June 13, 2022 (last updated February 23, 2025)
The OnePress Social Locker WordPress plugin through 5.6.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
Attacker Value
Unknown

CVE-2022-1605

Disclosure Date: June 13, 2022 (last updated February 23, 2025)
The Email Users WordPress plugin through 4.8.8 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and change the notification settings of arbitrary users
Attacker Value
Unknown

CVE-2022-1594

Disclosure Date: June 13, 2022 (last updated February 23, 2025)
The HC Custom WP-Admin URL WordPress plugin through 1.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack, allowing them to change the login URL