CVE-2025-64271: WordPress WP Plugin Manager plugin <= 1.4.7 - Cross Site Request Forgery (CSRF) vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in HasThemes WP Plugin Manager wp-plugin-manager allows Cross Site Request Forgery.This issue affects WP Plugin Manager: from n/a through <= 1.4.7.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64271?
CVE-2025-64271 has a moderate severity rating due to its potential for unauthorized actions through Cross-Site Request Forgery.
How do I fix CVE-2025-64271?
You can fix CVE-2025-64271 by updating the HasThemes WP Plugin Manager to a version higher than 1.4.7.
What software is affected by CVE-2025-64271?
CVE-2025-64271 affects HasThemes WP Plugin Manager versions up to and including 1.4.7.
Can CVE-2025-64271 lead to data breaches?
Yes, CVE-2025-64271 can potentially allow attackers to perform unauthorized actions, which may lead to data breaches.
Is CVE-2025-64271 easy to exploit?
CVE-2025-64271 can be easily exploited if the vulnerable plugin is present and protections against CSRF are not implemented.