CVE-2026-81426
The WC Vendors WordPress plugin before 2.7.2.1 does not have CSRF protection on some of its front-end order shipment status actions, which
CVSS
4.3
Medio
EPSS
—
KEV
—
Exploit Today
0
0-100
Publicado: 2 sept 2026 · Última mod.: 2 sept 2026 · CWE-352
Sin historial EPSS suficiente todavía.
The WC Vendors WordPress plugin before 2.7.2.1 does not have CSRF protection on some of its front-end order shipment status actions, which could allow attackers to make a logged-in vendor change the shipment status of their own orders via a crafted request.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-847708.8 ALT—
——0Unauthenticated Cross Site Request Forgery (CSRF) in Mang Board WP <= 2.3.8 versions.4hCVE-2026-847648.8 ALT—
——0Unauthenticated Cross Site Request Forgery (CSRF) in Simply Schedule Appointments <= 1.6.12.23 versions.4hCVE-2026-847597.1 ALT—
——0Unauthenticated Cross Site Request Forgery (CSRF) in Activity Log <= 2.13.1 versions.4hCVE-2026-666525.4 MED—
——0Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Tour allows Cross Site Request Forgery.
This issue affects Grand Tour: from n/a through 5.5.1.4hCVE-2026-814324.3 MED—
——0The JetStyleManager for Gutenberg WordPress plugin before 1.3.9 does not have CSRF protection on some of its AJAX actions, allowing attackers to make a logged-in user with the edit_posts capability (Contributor and above) delete or modify custom widget skins via a crafted request, provided they can trick the user into performing an action such as clicking a link.5hCVE-2026-187807.1 ALT—
——0Cross-Site request forgery (CSRF) vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows Cross Site Request Forgery.
This issue affects Talassoft Industrial Management Software: from V.4 before V.16.20h