PT-2025-51820 · WordPress · Download Plugins/Themes In Zip From Dashboard

Lorenzo Franchini

·

Published

2025-12-17

·

Updated

2025-12-17

·

CVE-2025-14399

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Download Plugins and Themes in ZIP from Dashboard plugin for WordPress versions through 1.9.6
Description The software is susceptible to a Cross-Site Request Forgery (CSRF) issue. This is due to inadequate or missing nonce validation within the download plugin bulk and download theme bulk functions. An unauthenticated attacker could potentially archive all site plugins and themes, placing them in the wp-content/uploads/ directory, by forging a request and tricking a site administrator into performing an action.
Recommendations Update the Download Plugins and Themes in ZIP from Dashboard plugin for WordPress to a version later than 1.9.6.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2025-14399

Affected Products

Download Plugins/Themes In Zip From Dashboard