← WordPress Vulnerabilities
WordPress security by component

Theme Editor

Theme Editor is a WordPress component with 5 published CVE records in this archive. The latest tracked vulnerability was published Apr 08, 2026; the highest CVE/CNA score is 9.6.

Plugin slug: theme-editor

CVE-2026-39640: Theme Editor: Code execution

Theme Editor is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is <= 3.2.

PublishedApr 08, 2026
Known safe version> 3.2
Safe version
Apr 08, 2026 CVE-2026-39640
Theme Editor: Code execution
Theme Editor is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is <= 3.2.
> 3.2
CVE9.6
NVDPending
Oct 18, 2025 CVE-2025-9890
Theme Editor: Code execution
Theme Editor is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE8.8
NVDPending
Aug 29, 2024 CVE-2022-2440
Theme Editor: Code execution
Theme Editor is affected by code execution. Exploitation requires an authenticated WordPress account. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE7.2
NVDPending
Mar 26, 2024 CVE-2023-6091
Theme Editor: Dangerous file upload
Theme Editor is affected by dangerous file upload. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
See mitigation notes
CVE7.2
NVDPending
Apr 05, 2021 CVE-2021-24154
Theme Editor: A security weakness
Theme Editor is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.9
NVD4.9