Input validation vulnerability in Update Theme and Plugins from Zip File 2.0.0

The Update Theme and Plugins from Zip File plugin for WordPress has a security vulnerability in versions up to, and including, 2.0.0. This vulnerability allows unauthenticated attackers to carry out malicious actions without the site administrator’s knowledge. These malicious actions could be done by tricking the site administrator into clicking a link. This vulnerability is caused by the lack of a security feature called a nonce, which should be used to validate requests.

Detected in:

Update Theme and Plugins from Zip File open vulnerable versions: >= * <= 2.0.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.