The insta-gallery plugin before 2.4.8 for WordPress has no nonce validation for qligg_dismiss_notice or qligg_form_item_delete.
CWE-352
CVE-2019-15781
The facebook-by-weblizar plugin before 2.8.5 for WordPress has CSRF.
CVE-2019-15660
The wp-members plugin before 3.2.8 for WordPress has CSRF.
CVE-2019-15645
The zoho-salesiq plugin before 1.0.9 for WordPress has CSRF.
CVE-2019-15648
The insert-or-embed-articulate-content-into-wordpress plugin before 4.29991 for WordPress has insufficient restrictions on deleting or renaming by a Subscriber.
CVE-2019-15491
openITCOCKPIT before 3.7.1 has CSRF, aka RVID 2-445b21.