Tag

#CSRF

articleHIGH 8.8

CVE-2026-78295: Unauthenticated Cross-Site Request Forgery (CSRF) in Xagio SEO Plugin

A critical vulnerability, CVE-2026-78295, with a CVSS score of 8.8, was discovered in the Xagio SEO plugin (versions <= 7.1.0.43) for WordPress. This unauthenticated Cross-Site Request Forgery (CSRF) vulnerability allows attackers to perform high-impact actions on affected sites. Although not actively exploited, the vulnerability's severity and potential impact warrant immediate attention. Organizations using the affected plugin versions should apply the available patch (version 7.1.0.44) as soon as possible.

1 source
articleCRITICAL 9.6

Critical CSRF and SSRF Vulnerability in Eclipse GlassFish: CVE-2026-12605

A critical vulnerability, CVE-2026-12605, with a CVSS score of 9.6, was discovered in Eclipse GlassFish versions 8.0.x before 8.0.4. This vulnerability combines Cross-Site Request Forgery (CSRF) and Server-Side Request Forgery (SSRF) flaws in the DownloadServlet ContentSources, allowing an attacker to leak the admin `gfresttoken` and potentially take over the Eclipse GlassFish domain. The vulnerability requires user interaction but can lead to full unauthenticated takeover of the domain. Immediate patching is recommended.

1 source
blogHIGH 8.8

Understanding and Defending Against CVE-2026-15988: Cross-Site Request Forgery in AI Engine Plugin

This educational analysis covers CVE-2026-15988, a Cross-Site Request Forgery (CSRF) vulnerability in the AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin. The vulnerability allows unauthenticated attackers to create new administrator accounts with attacker-supplied credentials. We will delve into the root cause, attack surface, exploitation mechanics, real-world impact, detection strategies, and defensive recommendations.

1 source
articleCRITICAL 9.1

Critical CSRF Vulnerability in Mojolicious::Plugin::Web::Auth::OAuth2 (CVE-2026-9733)

A critical vulnerability (CVE-2026-9733) with a CVSS score of 9.1 has been discovered in Mojolicious::Plugin::Web::Auth::OAuth2 versions up to 0.17. This vulnerability allows an attacker to hijack another user's session through cross-site request forgery (CSRF) due to a predictable state parameter. The vulnerability has not been actively exploited but poses a significant risk due to its high severity and potential impact. Immediate patching or mitigation is recommended.

1 source
articleMEDIUM 4.3

CVE-2024-32110: Cross-Site Request Forgery Vulnerability in WpEvently Plugin

A Cross-Site Request Forgery (CSRF) vulnerability was discovered in the WpEvently plugin, affecting versions from n/a through 4.1.2. This vulnerability, tracked as CVE-2024-32110, has a severity score of 4.3 and allows attackers to perform Cross-Site Request Forgery attacks.

1 source