NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 46571 | CVE-2012-5387 | Cross-site request forgery (CSRF) vulnerability in wlcms-plugin.php in the White Label CMS plugin before 1.5.1 for WordPress allows remote attackers to hijack the authentication of administrators for requests that modify the developer name via the wlcms_o_developer_name parameter in a save action to wp-admin/admin.php, as demonstrated by a developer name containing XSS sequences. | 2 | 6.8 | Medium | 2017-01-19 | 2013-08-19 | View | |
| 7127 | CVE-2017-5489 | Cross-site request forgery (CSRF) vulnerability in WordPress before 4.7.1 allows remote attackers to hijack the authentication of unspecified victims via vectors involving a Flash file upload. | 2 | 6.8 | Medium | 2017-07-18 | 2017-07-17 | View | |
| 11486 | CVE-2011-5226 | Cross-site request forgery (CSRF) vulnerability in wordpress_sentinel.php in the Sentinel plugin 1.0.0 for WordPress allows remote attackers to hijack the authentication of an administrator for requests that trigger snapshots. | 2 | 6.8 | Medium | 2017-01-07 | 2012-10-26 | View | |
| 45833 | CVE-2012-4448 | Cross-site request forgery (CSRF) vulnerability in wp-admin/index.php in WordPress 3.4.2 allows remote attackers to hijack the authentication of administrators for requests that modify an RSS URL via a dashboard_incoming_links edit action. | 2 | 6.8 | Medium | 2017-01-19 | 2012-10-01 | View | |
| 26803 | CVE-2015-5731 | Cross-site request forgery (CSRF) vulnerability in wp-admin/post.php in WordPress before 4.2.4 allows remote attackers to hijack the authentication of administrators for requests that lock a post, and consequently cause a denial of service (editing blockage), via a get-post-lock action. | 2 | 6.8 | Medium | 2017-01-19 | 2016-12-07 | View |
Page 2903 of 17672, showing 5 records out of 88360 total, starting on record 14511, ending on 14515