cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches fordownload-plugins-dashboard download-plugins-dashboard

Direction: descending
Jan 10, 2026

Download Plugins and Themes from Dashboard # CVE-2025-14399

CVE, Research URL

CVE-2025-14399

Date
Dec 17, 2025
Research Description
The Download Plugins and Themes in ZIP from Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.6. This is due to missing or incorrect nonce validation on the download_plugin_bulk and download_theme_bulk functions. This makes it possible for unauthenticated attackers to archive all the sites plugins and themes and place them in the `wp-content/uploads/` directory via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
max 1.9.7.
Status
vulnerable
Oct 12, 2024

Download Plugins and Themes from Dashboard # CVE-2024-9232

CVE, Research URL

CVE-2024-9232

Date
Oct 11, 2024
Research Description
The Download Plugins and Themes in ZIP from Dashboard plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.9.1. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected versions
max 1.9.2.
Status
vulnerable
Aug 17, 2024

Download Plugins and Themes from Dashboard # CVE-2024-7501

CVE, Research URL

CVE-2024-7501

Date
Aug 16, 2024
Research Description
The Download Plugins and Themes in ZIP from Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8.7. This is due to missing or incorrect nonce validation on the download_theme() function. This makes it possible for unauthenticated attackers to download arbitrary themes from the website via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. In versions prior to 1.8.6 it was possible to download the entire sites files.
Affected versions
max 1.8.8.
Status
vulnerable
Jun 07, 2024

Download Plugins and Themes from Dashboard # CVE-2019-17239

CVE, Research URL

CVE-2019-17239

Date
Oct 08, 2019
Research Description
includes/settings/class-alg-download-plugins-settings.php in the download-plugins-dashboard plugin through 1.5.0 for WordPress has multiple unauthenticated stored XSS issues.
Affected versions
max 1.6.0.
Status
vulnerable

Download Plugins and Themes from Dashboard # CVE-2024-35162

CVE, Research URL

CVE-2024-35162

Date
May 22, 2024
Research Description
Path traversal vulnerability exists in Download Plugins and Themes from Dashboard versions prior to 1.8.6. If this vulnerability is exploited, a remote authenticated attacker with "switch_themes" privilege may obtain arbitrary files on the server.
Affected versions
max 1.8.6.
Status
vulnerable