CVE-2025-14399: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-14399 is a Cross-Site Request Forgery (CSRF) vulnerability in the "Download Plugins and Themes in ZIP from Dashboard" WordPress plugin by WPCodeFactory. It affects all versions up to and including 1.9.6, and was published on December 17, 2025. The flaw allows unauthenticated attackers to archive a site's plugins and themes into the wp-content/uploads/ directory by tricking an administrator into clicking a malicious link. It carries a CVSS v3.1 base score of 4.3 (Medium) (Wordfence, Red Hat CVE).

Technical details

The root cause is missing or incorrect nonce validation (CWE-352: Cross-Site Request Forgery) on the download_plugin_bulk and download_theme_bulk functions within the plugin. Because these functions do not verify a WordPress nonce before executing, an attacker can craft a forged HTTP request that, when triggered by an authenticated administrator, causes the server to compress all installed plugins and themes into ZIP archives and place them in the publicly accessible wp-content/uploads/ directory. Exploitation requires social engineering — the attacker must trick a logged-in site administrator into clicking a crafted link or visiting a malicious page that submits the forged request (Wordfence, ENISA EUVD).

Impact

Successful exploitation results in a low-integrity impact: all installed plugin and theme files are archived and placed in the wp-content/uploads/ directory, which is typically publicly accessible. This exposes the site's plugin and theme source code to unauthenticated visitors, enabling reconnaissance for further attacks such as identifying vulnerable plugin versions or discovering hardcoded credentials. There is no direct confidentiality or availability impact, but the exposed file inventory can significantly lower the barrier for follow-on exploitation (Wordfence, ENISA EUVD).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2025-14399. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.013% (0.000130), indicating a very low probability of exploitation in the near term (Wordfence, Red Hat CVE).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the "Download Plugins and Themes in ZIP from Dashboard" plugin version ≤1.9.6 using tools like WPScan or by inspecting publicly visible plugin metadata.
  2. Craft forged request: Construct a malicious HTML page or URL that submits a POST request to the target WordPress site's admin-ajax endpoint (or equivalent), invoking the download_plugin_bulk or download_theme_bulk action without a valid nonce.
  3. Social engineering: Deliver the malicious link or page to a site administrator via phishing email, forum post, or other means, inducing them to click it while authenticated to the WordPress dashboard.
  4. Trigger archiving: When the administrator's browser submits the forged request, the plugin archives all installed plugins and/or themes into ZIP files and places them in wp-content/uploads/.
  5. Retrieve archives: The attacker directly downloads the ZIP archives from the publicly accessible wp-content/uploads/ directory, obtaining full source code of all plugins and themes for further analysis (Wordfence).

Indicators of compromise

  • File System: Unexpected ZIP archive files appearing in wp-content/uploads/ containing plugin or theme source code; file names consistent with bulk plugin/theme exports.
  • Logs: WordPress access logs showing POST requests to admin-ajax or admin endpoints invoking download_plugin_bulk or download_theme_bulk actions from unexpected IP addresses or referrers; subsequent GET requests to wp-content/uploads/ for newly created ZIP files from external IPs.
  • Network: Outbound or inbound HTTP requests to wp-content/uploads/ for large ZIP files shortly after an administrator session action.

Mitigation and workarounds

Update the "Download Plugins and Themes in ZIP from Dashboard" plugin to version 1.9.7 or later, which introduces proper nonce validation on the affected functions (WordPress Plugin Changeset). As an interim workaround, administrators can deactivate or remove the plugin until patching is feasible. Additionally, restricting access to the wp-content/uploads/ directory via server configuration (e.g., .htaccess rules) can limit the ability of attackers to retrieve any archives that may have been created.

Community reactions

The vulnerability was discovered and reported by Wordfence, which assigned the CVE and published the advisory on December 17, 2025 (Wordfence). Coverage has been limited to automated vulnerability aggregators and databases, with no notable independent researcher commentary or significant social media discussion observed.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management