plugin

Download Plugins Dashboard Vulnerabilities

5 known security issues reported for the Download Plugins Dashboard WordPress plugin. Most recent disclosed Dec 16, 2025.

5 medium

Running Download Plugins Dashboard on your site? Check whether your installed version is affected.

Scan your site free

Download Plugins and Themes from Dashboard <= 1.9.6 - Cross-Site Request Forgery to Bulk Plugin/Theme Archival

medium

The Download Plugins and Themes in ZIP from Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.6. This is due to missing or incorrect nonce validation on the download_plugin_bulk and download_theme_bulk functions. This makes it possible for unauthenticat...

CVSS:
4.3
Affected:
up to 1.9.6
Fixed in:
1.9.7
Disclosed:
Dec 16, 2025

CVE-2025-14399 on NVD →

Download Plugins and Themes in ZIP from Dashboard <= 1.9.1 - Reflected Cross-Site Scripting

medium

The Download Plugins and Themes in ZIP from Dashboard plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.9.1. This makes it possible for unauthenticated attackers to inject arbitrary web scr...

CVSS:
6.1
Affected:
up to 1.9.1
Fixed in:
1.9.2
Disclosed:
Oct 10, 2024

CVE-2024-9232 on NVD →

Download Plugins and Themes from Dashboard <= 1.8.7 - Cross-Site Request Forgery

medium

The Download Plugins and Themes in ZIP from Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8.7. This is due to missing or incorrect nonce validation on the download_theme() function. This makes it possible for unauthenticated attackers to download arbi...

CVSS:
4.2
Affected:
up to 1.8.7
Fixed in:
1.8.8
Disclosed:
Aug 15, 2024

CVE-2024-7501 on NVD →

Download Plugins and Themes from Dashboard <= 1.8.5 - Authenticated (Admin+) Arbitrary File Download

medium

The Download Plugins and Themes in ZIP from Dashboard plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.8.5 via the download_theme function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensi...

CVSS:
4.9
Affected:
up to 1.8.5
Fixed in:
1.8.6
Disclosed:
May 17, 2024

CVE-2024-35162 on NVD →

Download Plugins and Themes from Dashboard <= 1.5.0 - Unauthenticated Stored Cross-Site Scripting

medium

includes/settings/class-alg-download-plugins-settings.php in the download-plugins-dashboard plugin through 1.5.0 for WordPress has multiple unauthenticated stored XSS issues.

CVSS:
6.1
Affected:
up to 1.6.0
Fixed in:
1.6.0
Disclosed:
Oct 2, 2019

CVE-2019-17239 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database