Description
Cross-Site Request Forgery (CSRF) vulnerability in HasThemes WP Plugin Manager wp-plugin-manager allows Cross Site Request Forgery.This issue affects WP Plugin Manager: from n/a through <= 1.4.7.
Published: 2025-11-13
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a classic CSRF flaw that allows an attacker to forge a request from a victim’s authenticated WordPress session. By crafting a URL or form submission that the victim’s browser automatically includes their login cookies, the attacker could trigger actions tied to the plugin, such as installing, updating, or removing plugins, without the victim’s knowledge. The impact is the potential for unauthorized plugin manipulation, which could cascade to broader system compromise if malicious plugins are installed or critical plugins are disabled. The weakness is catalogued as CWE‑352.

Affected Systems

The vulnerability affects the HasThemes WP Plugin Manager plugin, version 1.4.7 and earlier. No specific patch version is cited, but any deployment of the plugin in those versions is at risk.

Risk and Exploitability

The CVSS score of 4.3 indicates a medium-security impact, while the EPSS score of less than 1% reflects a very low likelihood of widespread exploitation, and the issue is not listed in the CISA Known Exploited Vulnerabilities catalog. Typical CSRF exploitation requires that a victim be logged into the site with a sufficient privilege level and that they visit a malicious link or payload. With no further publicly disclosed exploitation patterns, the threat remains moderate but non‑negligible, especially for high‑value or highly‑privileged WordPress installations.

Generated by OpenCVE AI on April 29, 2026 at 20:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the HasThemes WP Plugin Manager plugin to a version newer than 1.4.7 or later, applying the vendor’s security patch.
  • If an immediate upgrade is not feasible, restrict or disable the plugin’s functionality until the patch can be applied, and consider removing the plugin altogether if it is not essential.
  • Maintain all other WordPress components—core, themes, and remaining plugins—at their latest secure releases and enforce strong administrative credentials and two‑factor authentication to minimize the impact of potential CSRF exploitation.

Generated by OpenCVE AI on April 29, 2026 at 20:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Fri, 13 Feb 2026 16:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:hasthemes:wp_plugin_manager:*:*:*:*:*:wordpress:*:*

Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Thu, 13 Nov 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Nov 2025 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Hasthemes
Hasthemes wp Plugin Manager
Wordpress
Wordpress wordpress
Vendors & Products Hasthemes
Hasthemes wp Plugin Manager
Wordpress
Wordpress wordpress

Thu, 13 Nov 2025 09:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in HasThemes WP Plugin Manager wp-plugin-manager allows Cross Site Request Forgery.This issue affects WP Plugin Manager: from n/a through <= 1.4.7.
Title WordPress WP Plugin Manager plugin <= 1.4.7 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References

Subscriptions

Hasthemes Wp Plugin Manager
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:13.325Z

Reserved: 2025-10-29T03:08:27.751Z

Link: CVE-2025-64271

cve-icon Vulnrichment

Updated: 2025-11-13T17:58:21.518Z

cve-icon NVD

Status : Modified

Published: 2025-11-13T10:15:52.470

Modified: 2026-04-27T16:16:39.283

Link: CVE-2025-64271

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T20:15:19Z

Weaknesses