Cross-Site Request Forgery in Theme Importer Plugin for WordPress
CVE-2025-10312
4.3MEDIUM
What is CVE-2025-10312?
The Theme Importer plugin for WordPress contains a vulnerability that exposes sites to Cross-Site Request Forgery (CSRF) attacks. This vulnerability arises from inadequate nonce validation in the theme-importer.php file, enabling unauthenticated attackers to exploit this flaw. By crafting a malicious request, attackers could potentially trick a site administrator into triggering arbitrary file downloads or executing harmful operations, should the administrator inadvertently click on a compromised link. This highlights the need for improved security measures to validate user requests within the plugin.
Affected Version(s)
Theme Importer * <= 1.0