Security
Headlines
HeadlinesLatestCVEs

Tag

#csrf

CVE-2022-47447: WordPress WP-Advanced-Search plugin <= 3.3.8 - Cross Site Request Forgery (CSRF) - Patchstack

Cross-Site Request Forgery (CSRF) vulnerability in Mathieu Chartier WordPress WP-Advanced-Search plugin <= 3.3.8 versions.

CVE
#csrf#vulnerability#wordpress#auth
CVE-2022-47446: WordPress Store Locator for WordPress with Google Maps – LotsOfLocales plugin <= 3.98.7 - Cross Site Request Forgery (CSRF) - Patchstack

Cross-Site Request Forgery (CSRF) vulnerability in Viadat Creations Store Locator for WordPress with Google Maps – LotsOfLocales plugin <= 3.98.7 versions.

CVE-2022-46816: WordPress Booking Ultra Pro Appointments Booking Calendar Plugin plugin <= 1.1.4 - Cross Site Request Forgery (CSRF) - Patchstack

Cross-Site Request Forgery (CSRF) vulnerability in Booking Ultra Pro Appointments Booking Calendar Plugin plugin <= 1.1.4 versions.

CVE-2022-46794: WordPress WooCommerce Weight Based Shipping plugin <= 5.4.1 - Cross Site Request Forgery (CSRF) Vulnerability - Patchstack

Cross-Site Request Forgery (CSRF) vulnerability in weightbasedshipping.Com WooCommerce Weight Based Shipping plugin <= 5.4.1 versions.

CVE-2022-45364: WordPress Drag and Drop Multiple File Upload – Contact Form 7 plugin <= 1.3.6.5 - Multiple CSRF vulnerabilities - Patchstack

Cross-Site Request Forgery (CSRF) vulnerability in Glen Don L. Mongaya Drag and Drop Multiple File Upload – Contact Form 7 plugin <= 1.3.6.5 versions.

CVE-2022-47180: WordPress Kopa Framework plugin <= 1.3.5 - Cross Site Request Forgery (CSRF) - Patchstack

Cross-Site Request Forgery (CSRF) vulnerability in Kopa Theme Kopa Framework plugin <= 1.3.5 versions.

CVE-2022-47152: WordPress clickfunnels plugin <= 3.1.1 - Cross Site Request Forgery (CSRF) - Patchstack

Cross-Site Request Forgery (CSRF) vulnerability in Etison, LLC ClickFunnels plugin <= 3.1.1 versions.

GetSimple CMS 3.3.16 Shell Upload

GetSimple CMS version 3.3.16 suffers from a remote shell upload vulnerability.

LeadPro CRM 1.0 SQL Injection

LeadPro CRM version 1.0 suffers from a remote SQL injection vulnerability.