← WordPress Vulnerabilities
WordPress security by component

Theme Editor

Theme Editor (theme-editor) is a WordPress plugin with 6 published CVE records in this archive. The latest tracked vulnerability was published Aug 01, 2026; the highest published CVSS base score is 9.6.

Plugin slug: theme-editor

CVE-2025-14469: Theme Editor lets forged administrator requests alter child-theme CSS

Theme Editor through 3.1 does not validate a nonce in the ms_update AJAX action. An unauthenticated attacker can prepare a forged request containing attacker-controlled child-theme CSS; if a logged-in Administrator is induced to submit it, the action modifies the site's theme styles.

PublishedAug 01, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for theme-editor
Safe version
Aug 01, 2026 CVE-2025-14469
Theme Editor lets forged administrator requests alter child-theme CSS
Theme Editor through 3.1 does not validate a nonce in the ms_update AJAX action. An unauthenticated attacker can prepare a forged request containing attacker-controlled child-theme CSS; if a logged-in Administrator is induced to submit it, the action modifies the site's theme styles.
See mitigation notes
CVE4.3
NVDPending
Apr 08, 2026 CVE-2026-39640
Theme Editor: Code execution
Theme Editor is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is <= 3.2.
See mitigation notes
CVE9.6
NVDPending
Oct 18, 2025 CVE-2025-9890
Theme Editor: Code execution
Theme Editor is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE8.8
NVDPending
Aug 29, 2024 CVE-2022-2440
Theme Editor: Code execution
Theme Editor is affected by code execution. Exploitation requires an authenticated WordPress account. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE7.2
NVDPending
Mar 26, 2024 CVE-2023-6091
Theme Editor: Dangerous file upload
Theme Editor is affected by dangerous file upload. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
See mitigation notes
CVE7.2
NVDPending
Apr 05, 2021 CVE-2021-24154
Theme Editor: A security weakness
Theme Editor is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVEPending
NVD4.9