Cross-Site Request Forgery in Hack Repair Guy's Plugin Archiver for WordPress
CVE-2025-10188

5.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
17 September 2025

What is CVE-2025-10188?

The Hack Repair Guy's Plugin Archiver for WordPress is susceptible to Cross-Site Request Forgery (CSRF) due to inadequate nonce validation in its bulk_remove() function. This vulnerability allows an unauthenticated attacker to execute arbitrary directory deletions within the /wp-content folder if they can trick an administrator into clicking a malicious link. This poses significant risks to the integrity and security of WordPress sites utilizing this plugin, potentially leading to unauthorized data loss or manipulation.

Affected Version(s)

The Hack Repair Guy's Plugin Archiver * <= 2.0.4

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jonas Benjamin Friedli
.
CVE-2025-10188 : Cross-Site Request Forgery in Hack Repair Guy's Plugin Archiver for WordPress