cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches fortheme-editor theme-editor

Direction: ascending
Jun 07, 2024

Theme Editor # CVE-2023-6091

CVE, Research URL

CVE-2023-6091

Application

Theme Editor

Date
Mar 27, 2024
Research Description
Unrestricted Upload of File with Dangerous Type vulnerability in mndpsingh287 Theme Editor.This issue affects Theme Editor: from n/a through 2.7.1.
Affected versions
max 2.8.
Status
vulnerable

Theme Editor # CVE-2021-24154

CVE, Research URL

CVE-2021-24154

Application

Theme Editor

Date
Apr 06, 2021
Research Description
The Theme Editor WordPress plugin before 2.6 did not validate the GET file parameter before passing it to the download_file() function, allowing administrators to download arbitrary files on the web server, such as /etc/passwd
Affected versions
max 2.6.
Status
vulnerable
Aug 29, 2024

Theme Editor # CVE-2022-2440

CVE, Research URL

CVE-2022-2440

Application

Theme Editor

Date
Aug 29, 2024
Research Description
The Theme Editor plugin for WordPress is vulnerable to deserialization of untrusted input via the 'images_array' parameter in versions up to, and including 2.8. This makes it possible for authenticated attackers with administrative privileges to call files using a PHAR wrapper that will deserialize and call arbitrary PHP Objects that can be used to perform a variety of malicious actions granted a POP chain is also present. It also requires that the attacker is successful in uploading a file with the serialized payload.
Affected versions
max 2.9.
Status
vulnerable
Nov 10, 2025

Theme Editor # CVE-2025-9890

CVE, Research URL

CVE-2025-9890

Application

Theme Editor

Date
Oct 18, 2025
Research Description
The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0. This is due to missing or incorrect nonce validation on the 'theme_editor_theme' page. This makes it possible for unauthenticated attackers to achieve remote code execution via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
max 3.1.
Status
vulnerable
Apr 14, 2026

Theme Editor # CVE-2026-39640

CVE, Research URL

CVE-2026-39640

Application

Theme Editor

Date
Apr 08, 2026
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in mndpsingh287 Theme Editor theme-editor allows Code Injection.This issue affects Theme Editor: from n/a through <= 3.2.
Affected versions
max 3.2.
Status
vulnerable
Jun 16, 2026

Theme Editor # 952ed32b3608d02bd294707ac8c2a1863d2e9f29

Application

Theme Editor

Date
Feb 13, 2021
Research Description
Theme Editor [theme-editor] < 2.6 WordPress Theme Editor plugin <= 2.5 - Multiple Authenticated Arbitrary File Download vulnerabilities Multiple Authenticated Arbitrary File Download vulnerabilities found by Nguyen Van Khanh and WPScan security research team in WordPress Theme Editor plugin (versions <= 2.5).
Affected versions
max 2.6.
Status
vulnerable

Theme Editor # 5afeaf8ad2061adae90a1eaa2c3420f1519a1703

Application

Theme Editor

Date
Sep 30, 2019
Research Description
Theme Editor [theme-editor] < 2.2 Theme Editor <= 2.1 - Cross-Site Request Forgery The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1. This is due to missing or incorrect nonce validation on the [function-name] function. This makes it possible for unauthenticated attackers to [state the impact of the vulnerability] via forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
max 2.2.
Status
vulnerable

Theme Editor # 20d300b08b5231c50599bdff0a4ad2718c0d655e

Application

Theme Editor

Date
Sep 30, 2019
Research Description
Theme Editor [theme-editor] < 2.2 WordPress Theme Editor plugin <= 2.1 - Multiple vulnerabilities Multiple vulnerabilities (CSRF, insufficient permission checking, arbitrary file upload) found by WebARX in WordPress Theme Editor plugin (versions <= 2.1).
Affected versions
max 2.2.
Status
vulnerable

Theme Editor # 9b660e2e-5cf8-4cf2-a307-989e150c37f9

Application

Theme Editor

Date
-
Research Description
Theme Editor [theme-editor] < 2.2 Theme Editor &lt; 2.2 - Multiple Vulnerabilities Versions 2.1 and lower of the &quot;theme-editor&quot; plugin are affected by multiple vulnerabilities such as CSRF, insufficient permission checking, arbitrary file upload and the ability to interact with folders/files on the server in most ways you can imagine. These vulnerabilities (aside from CSRF) require access to any account, regardless of its role.
Affected versions
max 2.2.
Status
vulnerable
Aug 02, 2026

Theme Editor # CVE-2025-14469

CVE, Research URL

CVE-2025-14469

Application

Theme Editor

Date
Aug 01, 2026
Research Description
The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1. This is due to missing nonce validation on the ms_update AJAX action. This makes it possible for unauthenticated attackers to modify child theme CSS styles via a forged request granted they can trick an administrator into performing an action such as clicking on a link.
Affected versions
max 3.2.
Status
vulnerable