Beta

Report

Plugin Central <= 2.5.1 is vulnerable to CSRF to Arbitrary File Deletion vulnerability

Unauthenticated
Published
2025-04-23

The Plugin Central plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.1. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php), granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS

Score:7.4

Severity:High

Version: 2.5.1

The plugin vendor has not patched this vulnerability at the moment.