{"id":"CVE-2020-36761","details":"The Top 10 plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.10.4. This is due to missing or incorrect nonce validation on the tptn_export_tables() function. This makes it possible for unauthenticated attackers to generate an export of the top 10 table via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","modified":"2026-04-02T06:08:45.870948Z","published":"2023-07-12T08:15:09.470Z","references":[{"type":"FIX","url":"https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2368373%40top-10&new=2368373%40top-10&sfp_email=&sfph_mail="},{"type":"FIX","url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f0af86e4-c30b-49e2-ad6a-97a415a74d18?source=cve"},{"type":"EVIDENCE","url":"https://blog.nintechnet.com/25-wordpress-plugins-vulnerable-to-csrf-attacks/"},{"type":"EVIDENCE","url":"https://blog.nintechnet.com/more-wordpress-plugins-and-themes-vulnerable-to-csrf-attacks/"},{"type":"EVIDENCE","url":"https://blog.nintechnet.com/multiple-wordpress-plugins-fixed-csrf-vulnerabilities-part-1/"},{"type":"EVIDENCE","url":"https://blog.nintechnet.com/multiple-wordpress-plugins-fixed-csrf-vulnerabilities-part-2/"},{"type":"EVIDENCE","url":"https://blog.nintechnet.com/multiple-wordpress-plugins-fixed-csrf-vulnerabilities-part-4/"},{"type":"EVIDENCE","url":"https://blog.nintechnet.com/multiple-wordpress-plugins-fixed-csrf-vulnerabilities-part-3/"},{"type":"EVIDENCE","url":"https://blog.nintechnet.com/multiple-wordpress-plugins-fixed-csrf-vulnerabilities-part-5/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/webberzone/top-10","events":[{"introduced":"0"},{"last_affected":"193dd644742de7a4511f6cc348e2b93994b6ae6e"}],"database_specific":{"versions":[{"introduced":"0"},{"last_affected":"2.9.4"}]}}],"versions":["2.2.2","v1.9.10","v1.9.10.1","v1.9.9.2","v2.0.0","v2.0.1","v2.0.2","v2.0.3","v2.1.0","v2.1.0-beta1","v2.2.0","v2.2.1","v2.2.3","v2.2.4","v2.3.0","v2.4.0","v2.4.0-beta1","v2.4.1","v2.4.2","v2.4.3","v2.4.4","v2.5.0","v2.5.1","v2.5.2","v2.5.3","v2.5.4","v2.5.5","v2.5.6","v2.5.7","v2.6.0","v2.6.1","v2.6.2","v2.6.3","v2.7.0","v2.8.0","v2.9.0","v2.9.1","v2.9.2","v2.9.3","v2.9.4"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-36761.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"}]}