WordPress Plugin Vulnerabilities

Doppler Forms < 2.6.0 - Subscriber+ Limited Plugin Installation

Description

The plugin registers an AJAX action install_extension without verifying user capabilities or using a nonce. As a result, any authenticated user — including those with the Subscriber role — can install and activate additional plugins (limited to those whitelisted by the main plugin).

Proof of Concept

Affects Plugins

Fixed in 2.6.0

References

Classification

Type
NO AUTHORISATION
CWE

Miscellaneous

Original Researcher
Khaled Alenazi (Nxploited)
Submitter
Khaled Alenazi (Nxploited)
Submitter website
Verified
Yes

Timeline

Publicly Published
2025-10-08 (about 2 months ago)
Added
2025-10-01 (about 2 months ago)
Last Updated
2025-10-13 (about 2 months ago)

Other