
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14399 is a Cross-Site Request Forgery (CSRF) vulnerability in the "Download Plugins and Themes in ZIP from Dashboard" WordPress plugin by WPCodeFactory. It affects all versions up to and including 1.9.6, and was published on December 17, 2025. The flaw allows unauthenticated attackers to archive a site's plugins and themes into the wp-content/uploads/ directory by tricking an administrator into clicking a malicious link. It carries a CVSS v3.1 base score of 4.3 (Medium) (Wordfence, Red Hat CVE).
The root cause is missing or incorrect nonce validation (CWE-352: Cross-Site Request Forgery) on the download_plugin_bulk and download_theme_bulk functions within the plugin. Because these functions do not verify a WordPress nonce before executing, an attacker can craft a forged HTTP request that, when triggered by an authenticated administrator, causes the server to compress all installed plugins and themes into ZIP archives and place them in the publicly accessible wp-content/uploads/ directory. Exploitation requires social engineering — the attacker must trick a logged-in site administrator into clicking a crafted link or visiting a malicious page that submits the forged request (Wordfence, ENISA EUVD).
Successful exploitation results in a low-integrity impact: all installed plugin and theme files are archived and placed in the wp-content/uploads/ directory, which is typically publicly accessible. This exposes the site's plugin and theme source code to unauthenticated visitors, enabling reconnaissance for further attacks such as identifying vulnerable plugin versions or discovering hardcoded credentials. There is no direct confidentiality or availability impact, but the exposed file inventory can significantly lower the barrier for follow-on exploitation (Wordfence, ENISA EUVD).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2025-14399. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.013% (0.000130), indicating a very low probability of exploitation in the near term (Wordfence, Red Hat CVE).
download_plugin_bulk or download_theme_bulk action without a valid nonce.wp-content/uploads/.wp-content/uploads/ directory, obtaining full source code of all plugins and themes for further analysis (Wordfence).wp-content/uploads/ containing plugin or theme source code; file names consistent with bulk plugin/theme exports.download_plugin_bulk or download_theme_bulk actions from unexpected IP addresses or referrers; subsequent GET requests to wp-content/uploads/ for newly created ZIP files from external IPs.wp-content/uploads/ for large ZIP files shortly after an administrator session action.Update the "Download Plugins and Themes in ZIP from Dashboard" plugin to version 1.9.7 or later, which introduces proper nonce validation on the affected functions (WordPress Plugin Changeset). As an interim workaround, administrators can deactivate or remove the plugin until patching is feasible. Additionally, restricting access to the wp-content/uploads/ directory via server configuration (e.g., .htaccess rules) can limit the ability of attackers to retrieve any archives that may have been created.
The vulnerability was discovered and reported by Wordfence, which assigned the CVE and published the advisory on December 17, 2025 (Wordfence). Coverage has been limited to automated vulnerability aggregators and databases, with no notable independent researcher commentary or significant social media discussion observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."