Cross-Site Request Forgery Vulnerability in Theme Editor for WordPress
CVE-2025-14469
4.3MEDIUM
What is CVE-2025-14469?
The Theme Editor plugin for WordPress contains a Cross-Site Request Forgery vulnerability that affects all versions up to and including 3.1. This flaw arises from the lack of nonce validation during the ms_update AJAX action, enabling unauthenticated attackers to exploit this weakness. By deceiving an administrator into clicking a malicious link, attackers can manipulate child theme CSS styles through a forged request, compromising the integrity of the website's appearance and functionality. Website administrators are advised to update the plugin to mitigate potential threats.
Affected Version(s)
Theme Editor 0 <= 3.1