What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in Jeff Sherk Update Theme and Plugins from Zip File plugin <= 2.0.0 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in Jeff Sherk Update Theme and Plugins from Zip File plugin <= 2.0.0 versions.
Explanation of Vulnerability in Simple Terms
The Update Theme and Plugins from Zip File plugin for WordPress is vulnerable to cross-site request forgery (CSRF). An attacker can craft a malicious webpage that, when visited by a logged-in site administrator, triggers unintended plugin or theme uploads or updates without the admin's knowledge or consent. This requires the victim to visit the attacker's page while authenticated to the WordPress site.
What an attacker can do
Trick a site admin into uploading or updating plugins/themes without their knowledge by visiting a malicious webpage.
Potential impact on your site
An attacker can upload malicious plugins or themes to your site if an admin visits a crafted link while logged in.
Conditions required to exploit
Site admin must be logged into WordPress and visit an attacker-controlled webpage while authenticated.
Key dates
External resources
Related vulnerabilities