The visitors-traffic-real-time-statistics plugin before 1.12 for WordPress has CSRF in the settings page.
CWE-352
CVE-2019-15832
The visitors-traffic-real-time-statistics plugin before 1.13 for WordPress has CSRF.
CVE-2019-15834
The webp-converter-for-media plugin before 1.0.3 for WordPress has CSRF.
CVE-2019-15835
The wp-better-permalinks plugin before 3.0.5 for WordPress has CSRF.
CVE-2019-15769
The handl-utm-grabber plugin before 2.6.5 for WordPress has CSRF via add_option and update_option.
CVE-2019-15770
The woo-address-book plugin before 1.6.0 for WordPress has save calls without nonce verification checks.