Description Enabling and disabling installed H5P libraries did not include the necessary token to prevent a CSRF risk. Remediation References CVE-2022-2986 Related Vulnerabilities WordPress Plugin Ultimate Member-User Profile, Registration, Login, Member Directory, Content Restriction & Membership Cross-Site Scripting (2.0.25) ProjectSend Improper Privilege Management Vulnerability (CVE-2020-28874) TYPO3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2012-6147) MySQL CVE-2023-21875 Vulnerability (CVE-2023-21875) WordPress Plugin UK Cookie Cross-Site Request Forgery (1.1) Severity High Classification CVE-2022-2986 CWE-352 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Tags Missing Update Known Vulnerabilities