Vulnerabilities and security researches fordownload-plugins-dashboard download-plugins-dashboard
Direction: descendingJan 10, 2026
Download Plugins and Themes from Dashboard # CVE-2025-14399
- CVE, Research URL
- Application
- Date
- Dec 17, 2025
- Research Description
- The Download Plugins and Themes in ZIP from Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.6. This is due to missing or incorrect nonce validation on the download_plugin_bulk and download_theme_bulk functions. This makes it possible for unauthenticated attackers to archive all the sites plugins and themes and place them in the `wp-content/uploads/` directory via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
- Affected versions
-
max 1.9.7.
- Status
-
vulnerable
Oct 12, 2024
Download Plugins and Themes from Dashboard # CVE-2024-9232
- CVE, Research URL
- Application
- Date
- Oct 11, 2024
- Research Description
- The Download Plugins and Themes in ZIP from Dashboard plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.9.1. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
- Affected versions
-
max 1.9.2.
- Status
-
vulnerable
Aug 17, 2024
Download Plugins and Themes from Dashboard # CVE-2024-7501
- CVE, Research URL
- Application
- Date
- Aug 16, 2024
- Research Description
- The Download Plugins and Themes in ZIP from Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8.7. This is due to missing or incorrect nonce validation on the download_theme() function. This makes it possible for unauthenticated attackers to download arbitrary themes from the website via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. In versions prior to 1.8.6 it was possible to download the entire sites files.
- Affected versions
-
max 1.8.8.
- Status
-
vulnerable
Jun 07, 2024
Download Plugins and Themes from Dashboard # CVE-2019-17239
- CVE, Research URL
- Application
- Date
- Oct 08, 2019
- Research Description
- includes/settings/class-alg-download-plugins-settings.php in the download-plugins-dashboard plugin through 1.5.0 for WordPress has multiple unauthenticated stored XSS issues.
- Affected versions
-
max 1.6.0.
- Status
-
vulnerable
Download Plugins and Themes from Dashboard # CVE-2024-35162
- CVE, Research URL
- Application
- Date
- May 22, 2024
- Research Description
- Path traversal vulnerability exists in Download Plugins and Themes from Dashboard versions prior to 1.8.6. If this vulnerability is exploited, a remote authenticated attacker with "switch_themes" privilege may obtain arbitrary files on the server.
- Affected versions
-
max 1.8.6.
- Status
-
vulnerable