The framework for plugins and themes contain a Cross-Site Request Forgery (CSRF) vulnerability due to a missing nonce check in the {slug}_submit-uninstall-reason AJAX action, which makes it possible for attackers to sending the uninstall reason, which also includes personal data (such as the admin's name, email, IP address), and server information via a forged request if they can trick an administrator into performing an action such as clicking on a link. Note: The {slug} is a plugin or theme slug configured in the framework.