Subscriptions
Tracking
Sign in to view the affected projects.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 17 Dec 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 17 Dec 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress Wpfactory Wpfactory download Plugins And Themes From Dashboard |
|
| Vendors & Products |
Wordpress
Wordpress wordpress Wpfactory Wpfactory download Plugins And Themes From Dashboard |
Wed, 17 Dec 2025 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Download Plugins and Themes in ZIP from Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.6. This is due to missing or incorrect nonce validation on the download_plugin_bulk and download_theme_bulk functions. This makes it possible for unauthenticated attackers to archive all the sites plugins and themes and place them in the `wp-content/uploads/` directory via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. | |
| Title | Download Plugins and Themes from Dashboard <= 1.9.6 - Cross-Site Request Forgery to Bulk Plugin/Theme Archival | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-12-17T21:44:12.097Z
Reserved: 2025-12-10T01:12:16.135Z
Link: CVE-2025-14399
Updated: 2025-12-17T21:44:06.524Z
Status : Awaiting Analysis
Published: 2025-12-17T08:15:43.000
Modified: 2025-12-18T15:08:06.237
Link: CVE-2025-14399
No data.
OpenCVE Enrichment
Updated: 2025-12-17T14:28:30Z