Unauthorized Data Modification in Accelerate Theme for WordPress
CVE-2025-9266
4.3MEDIUM
What is CVE-2025-9266?
The Accelerate theme for WordPress contains a vulnerability that allows authenticated users with Subscriber-level access or higher to bypass security measures due to a missing capability check on the enqueue_scripts() function. This flaw enables attackers to install and activate the ThemeGrill Demo Importer plugin, compromising the integrity of the site. Users are encouraged to update to version 1.5.4 or later to mitigate this risk.
Affected Version(s)
Accelerate 0 <= 1.5.3