The eelv-newsletter plugin prior to 4.6.1 for WordPress has CSRF in the address book.
eelv newsletter project eelv newsletter