🛡️ CVE Monitor
Dịch vụ / phần mềm liên quan: WordPress

Mô tả

The Download Plugins and Themes in ZIP from Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.6. This is due to missing or incorrect nonce validation on the download_plugin_bulk and download_theme_bulk functions. This makes it possible for unauthenticated attackers to archive all the sites plugins and themes and place them in the `wp-content/uploads/` directory via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Chi tiết

Trạng tháiDeferred
Điểm CVSS4.3 (v3.1)
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Ngày công bố15:15 17/12/2025
Ngày cập nhật17:10 28/09/2026
Nguồn dữ liệunvd

CWE

  • CWE-352

Sản phẩm bị ảnh hưởng

Nguồn dữ liệu chưa cung cấp thông tin sản phẩm chi tiết.

Tài liệu tham khảo

Lịch sử thay đổi

Thời gianLoạiTrườngGiá trị cũGiá trị mới
17:17 28/09/2026 CREATED cve MEDIUM

Tất cả thời gian trên trang này hiển thị theo giờ Việt Nam (GMT+7).