CVE-2025-64271: WordPress WP Plugin Manager plugin <= 1.4.7 - Cross Site Request Forgery (CSRF) vulnerability

Published Nov 13, 2025
·
Updated

Cross-Site Request Forgery (CSRF) vulnerability in HasThemes WP Plugin Manager wp-plugin-manager allows Cross Site Request Forgery.This issue affects WP Plugin Manager: from n/a through <= 1.4.7.

Affected Software

3 affected components
HasThemes WP Plugin Manager<=1.4.7
WordPress WP Plugin Manager<=1.4.7
HasThemes Wp Plugin Manager Wordpress<1.4.8

Event History

Nov 13, 2025
CVE Published
via MITRE·09:24 AM
Data Sourced
via MITRE·09:24 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-64271?

CVE-2025-64271 has a moderate severity rating due to its potential for unauthorized actions through Cross-Site Request Forgery.

2

How do I fix CVE-2025-64271?

You can fix CVE-2025-64271 by updating the HasThemes WP Plugin Manager to a version higher than 1.4.7.

3

What software is affected by CVE-2025-64271?

CVE-2025-64271 affects HasThemes WP Plugin Manager versions up to and including 1.4.7.

4

Can CVE-2025-64271 lead to data breaches?

Yes, CVE-2025-64271 can potentially allow attackers to perform unauthorized actions, which may lead to data breaches.

5

Is CVE-2025-64271 easy to exploit?

CVE-2025-64271 can be easily exploited if the vulnerable plugin is present and protections against CSRF are not implemented.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203