Description
Cross-Site Request Forgery (CSRF) vulnerability in Rohit Choudhary Theme Duplicator theme-duplicator allows Cross Site Request Forgery.This issue affects Theme Duplicator: from n/a through <= 1.1.
Published: 2025-04-01
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a Cross‑Site Request Forgery flaw that allows an attacker to trigger privileged actions within the WordPress site by tricking an authenticated user into submitting a forged request. The issue resides in the Theme Duplicator plugin version 1.1 or earlier, where no CSRF token is enforced on certain operations. If exploited, a malicious actor could perform actions such as duplicating or modifying theme data without providing valid credentials, potentially leading to data tampering or site compromise. The flaw is classified as CWE‑352 and poses a risk of unauthorized state‑changing operations but does not directly expose information or lead to remote code execution.

Affected Systems

The affected asset is the WordPress Theme Duplicator plugin developed by Rohit Choudhary. Versions from the initial release through 1.1 are vulnerable. No other plugin or WordPress core component has been identified as affected.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity, and the EPSS score of less than 1% shows a very low probability of exploitation at the time of this analysis. The vulnerability is not listed in the CISA KEV catalog. CSRF attacks typically require a victim user who is already authenticated to the site; an attacker can induce the user to visit a crafted URL that submits a form or triggers an HTTP request with the victim’s session cookie. Because the flaw lacks additional authentication checks, the attack vector is straightforward for a user with any site role. The low EPSS suggests that widespread exploitation is unlikely, but the existence of the flaw warrants attention if the plugin remains in use on a live site.

Generated by OpenCVE AI on May 1, 2026 at 01:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Theme Duplicator to a version newer than 1.1 once available
  • If an upgrade is not possible, disable or remove the plugin to eliminate the CSRF surface
  • Configure WordPress or the server to enforce CSRF tokens on all state‑changing requests and restrict Theme Duplicator actions to the admin role only

Generated by OpenCVE AI on May 1, 2026 at 01:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-9188 Cross-Site Request Forgery (CSRF) vulnerability in Rohit Choudhary Theme Duplicator allows Cross Site Request Forgery. This issue affects Theme Duplicator: from n/a through 1.1.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Rohit Choudhary Theme Duplicator allows Cross Site Request Forgery. This issue affects Theme Duplicator: from n/a through 1.1. Cross-Site Request Forgery (CSRF) vulnerability in Rohit Choudhary Theme Duplicator theme-duplicator allows Cross Site Request Forgery.This issue affects Theme Duplicator: from n/a through <= 1.1.
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Tue, 01 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Apr 2025 15:00:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Rohit Choudhary Theme Duplicator allows Cross Site Request Forgery. This issue affects Theme Duplicator: from n/a through 1.1.
Title WordPress Theme Duplicator Plugin <= 1.1 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:14.218Z

Reserved: 2025-04-01T13:20:50.880Z

Link: CVE-2025-31845

cve-icon Vulnrichment

Updated: 2025-04-01T16:05:57.540Z

cve-icon NVD

Status : Deferred

Published: 2025-04-01T15:16:25.337

Modified: 2026-04-23T15:28:24.403

Link: CVE-2025-31845

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T02:00:06Z

Weaknesses