Description
Cross-Site Request Forgery (CSRF) vulnerability in Shahjada WPDM – Premium Packages wpdm-premium-packages allows Cross Site Request Forgery.This issue affects WPDM – Premium Packages: from n/a through <= 6.0.2.
Published: 2025-08-14
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A CSRF flaw exists in the WPDM – Premium Packages plugin, allowing a malicious site to make state‑changing requests on behalf of an authenticated WordPress administrator. The vulnerability stems from missing or insufficient anti‑CSRF tokens (CWE‑352) and can be exploited by sending a crafted request that the victim’s browser will automatically submit. While it does not directly grant remote code execution, an attacker can modify plugin configuration or potentially lift restrictions, compromising the confidentiality and integrity of site content.

Affected Systems

The flaw affects the WPDM – Premium Packages plugin from indeterminate starting versions through 6.0.2, according to the vendor. Any WordPress installation running a vulnerable version of this plugin is at risk.

Risk and Exploitability

The CVSS score of 4.3 reflects a moderate impact and requires user interaction, which suggests that exploitation relies on persuading an authenticated administrator to visit a malicious site. The EPSS score of less than 1% indicates that, at present, attacks are unlikely, and the vulnerability is not currently listed in the CISA KEV catalog. The likely attack path involves a phishing or drive‑by site that tricks a logged‑in user into performing a privileged request, so the overall risk is moderate but mitigated by the requirement for victim participation. Timely patching remains the most effective countermeasure.

Generated by OpenCVE AI on April 30, 2026 at 08:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade WPDM – Premium Packages to version 6.0.3 or later
  • Disable or restrict the plugin for non‑administrator users until the vulnerability is addressed
  • Enable and verify WordPress's built‑in CSRF protection by ensuring that all admin form submissions include a valid nonce

Generated by OpenCVE AI on April 30, 2026 at 08:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-24914 Cross-Site Request Forgery (CSRF) vulnerability in Shahjada WPDM – Premium Packages allows Cross Site Request Forgery. This issue affects WPDM – Premium Packages: from n/a through 6.0.2.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Shahjada WPDM – Premium Packages allows Cross Site Request Forgery. This issue affects WPDM – Premium Packages: from n/a through 6.0.2. Cross-Site Request Forgery (CSRF) vulnerability in Shahjada WPDM – Premium Packages wpdm-premium-packages allows Cross Site Request Forgery.This issue affects WPDM – Premium Packages: from n/a through <= 6.0.2.
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Fri, 15 Aug 2025 08:30:00 +0000

Type Values Removed Values Added
First Time appeared Shahjada
Shahjada wpdm Premium Packages
Wordpress
Wordpress wordpress
Vendors & Products Shahjada
Shahjada wpdm Premium Packages
Wordpress
Wordpress wordpress

Thu, 14 Aug 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 14 Aug 2025 18:30:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Shahjada WPDM – Premium Packages allows Cross Site Request Forgery. This issue affects WPDM – Premium Packages: from n/a through 6.0.2.
Title WordPress WPDM – Premium Packages Plugin <= 6.0.2 - Cross Site Request Forgery (CSRF) Vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

Shahjada Wpdm Premium Packages
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:36.885Z

Reserved: 2025-07-28T10:56:33.522Z

Link: CVE-2025-54732

cve-icon Vulnrichment

Updated: 2025-08-14T19:33:39.977Z

cve-icon NVD

Status : Deferred

Published: 2025-08-14T19:15:40.440

Modified: 2026-04-23T15:32:54.327

Link: CVE-2025-54732

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T09:00:20Z

Weaknesses