NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
39085  CVE-2013-3250  Cross-site request forgery (CSRF) vulnerability in the WP Maintenance Mode plugin before 1.8.8 for WordPress allows remote attackers to hijack the authentication of arbitrary users for requests that modify this plugin"s settings.    6.8  Medium  2017-01-18  2013-06-24  View
36108  CVE-2014-9401  Cross-site request forgery (CSRF) vulnerability in the WP Limit Posts Automatically plugin 0.7 and earlier for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the lpa_post_letters parameter in the wp-limit-posts-automatically.php page to wp-admin/options-general.php.    6.8  Medium  2017-01-19  2015-01-12  View
38647  CVE-2013-2705  Cross-site request forgery (CSRF) vulnerability in the WordPress Simple Paypal Shopping Cart plugin before 3.6 for WordPress allows remote attackers to hijack the authentication of administrators for requests that change plugin settings.    6.8  Medium  2017-01-18  2014-05-14  View
39273  CVE-2013-3476  Cross-site request forgery (CSRF) vulnerability in the WordPress Related Posts plugin before 2.6.2 for WordPress allows remote attackers to hijack the authentication of users for requests that change settings via unspecified vectors.    6.8  Medium  2017-01-18  2014-06-03  View
32948  CVE-2014-5199  Cross-site request forgery (CSRF) vulnerability in the WordPress File Upload plugin (wp-file-upload) before 2.4.2 for WordPress allows remote attackers to hijack the authentication of administrators for requests that change plugin settings via unspecified vectors. NOTE: some of these details are obtained from third party information.    6.8  Medium  2017-01-19  2014-08-13  View

Page 14781 of 17672, showing 5 records out of 88360 total, starting on record 73901, ending on 73905

Actions