plugin

Theme Editor Vulnerabilities

7 known security issues reported for the Theme Editor WordPress plugin. Most recent disclosed Jul 31, 2026.

4 high 3 medium

Running Theme Editor on your site? Check whether your installed version is affected.

Scan your site free

Theme Editor <= 3.1 - Cross-Site Request Forgery to CSS Modification

medium

The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1. This is due to missing nonce validation on the ms_update AJAX action. This makes it possible for unauthenticated attackers to modify child theme CSS styles via a forged request granted they can t...

CVSS:
4.3
Affected:
up to 3.1
Fixed in:
3.2
Disclosed:
Jul 31, 2026

CVE-2025-14469 on NVD →

Theme Editor <= 3.2 - Cross-Site Request Forgery

medium

The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick...

CVSS:
4.3
Affected:
up to 3.2
Fix:
No patched version reported
Disclosed:
Feb 14, 2026

CVE-2026-39640 on NVD →

Theme Editor <= 3.0 - Cross-Site Request Forgery to Remote Code Execution

high

The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0. This is due to missing or incorrect nonce validation on the 'theme_editor_theme' page. This makes it possible for unauthenticated attackers to achieve remote code execution via a forged request g...

CVSS:
8.8
Affected:
up to 3.0
Fixed in:
3.1
Disclosed:
Oct 17, 2025

CVE-2025-9890 on NVD →

Theme Editor <= 2.8 - Authenticated (Admin+) PHAR Deserialization

high

The Theme Editor plugin for WordPress is vulnerable to deserialization of untrusted input via the 'images_array' parameter in versions up to, and including 2.8. This makes it possible for authenticated attackers with administrative privileges to call files using a PHAR wrapper that will deserialize and call arbitrary P...

CVSS:
7.2
Affected:
up to 2.8
Fixed in:
2.9
Disclosed:
Aug 28, 2024

CVE-2022-2440 on NVD →

Theme Editor <= 2.7.1 - Authenticated (Administrator+) Arbitrary File Upload

high

The Theme Editor plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 2.7.1. This makes it possible for authenticated attackers with administrator privileges or higher to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVSS:
7.2
Affected:
up to 2.7.1
Fixed in:
2.8
Disclosed:
Nov 20, 2023

CVE-2023-6091 on NVD →

Theme Editor <= 2.5 - Authenticated Arbitrary File Download

medium

The Theme Editor WordPress plugin before 2.6 did not validate the GET file parameter before passing it to the download_file() function, allowing administrators to download arbitrary files on the web server, such as /etc/passwd

CVSS:
4.9
Affected:
up to 2.5
Fixed in:
2.6
Disclosed:
Feb 13, 2021

CVE-2021-24154 on NVD →

Theme Editor <= 2.1 - Cross-Site Request Forgery

high

The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1. This is due to missing or incorrect nonce validation on the [function-name] function. This makes it possible for unauthenticated attackers to [state the impact of the vulnerability] via forged reques...

CVSS:
8.8
Affected:
up to 2.2
Fixed in:
2.2
Disclosed:
Sep 30, 2019

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database