Theme Editor <= 3.1 - Cross-Site Request Forgery to CSS Modification
medium
The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1. This is due to missing nonce validation on the ms_update AJAX action. This makes it possible for unauthenticated attackers to modify child theme CSS styles via a forged request granted they can t...
- CVSS:
- 4.3
- Affected:
- up to 3.1
- Fixed in:
- 3.2
- Disclosed:
- Jul 31, 2026
CVE-2025-14469 on NVD →
Theme Editor <= 3.2 - Cross-Site Request Forgery
medium
The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick...
- CVSS:
- 4.3
- Affected:
- up to 3.2
- Fix:
- No patched version reported
- Disclosed:
- Feb 14, 2026
CVE-2026-39640 on NVD →
Theme Editor <= 3.0 - Cross-Site Request Forgery to Remote Code Execution
high
The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0. This is due to missing or incorrect nonce validation on the 'theme_editor_theme' page. This makes it possible for unauthenticated attackers to achieve remote code execution via a forged request g...
- CVSS:
- 8.8
- Affected:
- up to 3.0
- Fixed in:
- 3.1
- Disclosed:
- Oct 17, 2025
CVE-2025-9890 on NVD →
Theme Editor <= 2.8 - Authenticated (Admin+) PHAR Deserialization
high
The Theme Editor plugin for WordPress is vulnerable to deserialization of untrusted input via the 'images_array' parameter in versions up to, and including 2.8. This makes it possible for authenticated attackers with administrative privileges to call files using a PHAR wrapper that will deserialize and call arbitrary P...
- CVSS:
- 7.2
- Affected:
- up to 2.8
- Fixed in:
- 2.9
- Disclosed:
- Aug 28, 2024
CVE-2022-2440 on NVD →
Theme Editor <= 2.7.1 - Authenticated (Administrator+) Arbitrary File Upload
high
The Theme Editor plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 2.7.1. This makes it possible for authenticated attackers with administrator privileges or higher to upload arbitrary files on the affected site's server which may make remote code execution possible.
- CVSS:
- 7.2
- Affected:
- up to 2.7.1
- Fixed in:
- 2.8
- Disclosed:
- Nov 20, 2023
CVE-2023-6091 on NVD →
Theme Editor <= 2.5 - Authenticated Arbitrary File Download
medium
The Theme Editor WordPress plugin before 2.6 did not validate the GET file parameter before passing it to the download_file() function, allowing administrators to download arbitrary files on the web server, such as /etc/passwd
- CVSS:
- 4.9
- Affected:
- up to 2.5
- Fixed in:
- 2.6
- Disclosed:
- Feb 13, 2021
CVE-2021-24154 on NVD →
Theme Editor <= 2.1 - Cross-Site Request Forgery
high
The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1. This is due to missing or incorrect nonce validation on the [function-name] function. This makes it possible for unauthenticated attackers to [state the impact of the vulnerability] via forged reques...
- CVSS:
- 8.8
- Affected:
- up to 2.2
- Fixed in:
- 2.2
- Disclosed:
- Sep 30, 2019
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database