Vulnerabilities and security researches fortheme-editor theme-editor
Direction: ascendingJun 07, 2024
Theme Editor # CVE-2023-6091
- CVE, Research URL
- Home page URL
- Application
- Date
- Mar 27, 2024
- Research Description
- Unrestricted Upload of File with Dangerous Type vulnerability in mndpsingh287 Theme Editor.This issue affects Theme Editor: from n/a through 2.7.1.
- Affected versions
-
max 2.8.
- Status
-
vulnerable
Theme Editor # CVE-2021-24154
- CVE, Research URL
- Home page URL
- Application
- Date
- Apr 06, 2021
- Research Description
- The Theme Editor WordPress plugin before 2.6 did not validate the GET file parameter before passing it to the download_file() function, allowing administrators to download arbitrary files on the web server, such as /etc/passwd
- Affected versions
-
max 2.6.
- Status
-
vulnerable
Aug 29, 2024
Theme Editor # CVE-2022-2440
- CVE, Research URL
- Home page URL
- Application
- Date
- Aug 29, 2024
- Research Description
- The Theme Editor plugin for WordPress is vulnerable to deserialization of untrusted input via the 'images_array' parameter in versions up to, and including 2.8. This makes it possible for authenticated attackers with administrative privileges to call files using a PHAR wrapper that will deserialize and call arbitrary PHP Objects that can be used to perform a variety of malicious actions granted a POP chain is also present. It also requires that the attacker is successful in uploading a file with the serialized payload.
- Affected versions
-
max 2.9.
- Status
-
vulnerable
Nov 10, 2025
Theme Editor # CVE-2025-9890
- CVE, Research URL
- Home page URL
- Application
- Date
- Oct 18, 2025
- Research Description
- The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0. This is due to missing or incorrect nonce validation on the 'theme_editor_theme' page. This makes it possible for unauthenticated attackers to achieve remote code execution via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
- Affected versions
-
max 3.1.
- Status
-
vulnerable
Apr 14, 2026
Theme Editor # CVE-2026-39640
- CVE, Research URL
- Home page URL
- Application
- Date
- Apr 08, 2026
- Research Description
- Cross-Site Request Forgery (CSRF) vulnerability in mndpsingh287 Theme Editor theme-editor allows Code Injection.This issue affects Theme Editor: from n/a through <= 3.2.
- Affected versions
-
max 3.2.
- Status
-
vulnerable
Jun 16, 2026
Theme Editor # 952ed32b3608d02bd294707ac8c2a1863d2e9f29
- CVE, Research URL
- Home page URL
- Application
- Date
- Feb 13, 2021
- Research Description
- Theme Editor [theme-editor] < 2.6 WordPress Theme Editor plugin <= 2.5 - Multiple Authenticated Arbitrary File Download vulnerabilities Multiple Authenticated Arbitrary File Download vulnerabilities found by Nguyen Van Khanh and WPScan security research team in WordPress Theme Editor plugin (versions <= 2.5).
- Affected versions
-
max 2.6.
- Status
-
vulnerable
Theme Editor # 5afeaf8ad2061adae90a1eaa2c3420f1519a1703
- CVE, Research URL
- Home page URL
- Application
- Date
- Sep 30, 2019
- Research Description
- Theme Editor [theme-editor] < 2.2 Theme Editor <= 2.1 - Cross-Site Request Forgery The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1. This is due to missing or incorrect nonce validation on the [function-name] function. This makes it possible for unauthenticated attackers to [state the impact of the vulnerability] via forged request granted they can trick a site administrator into performing an action such as clicking on a link.
- Affected versions
-
max 2.2.
- Status
-
vulnerable
Theme Editor # 20d300b08b5231c50599bdff0a4ad2718c0d655e
- CVE, Research URL
- Home page URL
- Application
- Date
- Sep 30, 2019
- Research Description
- Theme Editor [theme-editor] < 2.2 WordPress Theme Editor plugin <= 2.1 - Multiple vulnerabilities Multiple vulnerabilities (CSRF, insufficient permission checking, arbitrary file upload) found by WebARX in WordPress Theme Editor plugin (versions <= 2.1).
- Affected versions
-
max 2.2.
- Status
-
vulnerable
Theme Editor # 9b660e2e-5cf8-4cf2-a307-989e150c37f9
- CVE, Research URL
- Home page URL
- Application
- Date
- -
- Research Description
- Theme Editor [theme-editor] < 2.2 Theme Editor < 2.2 - Multiple Vulnerabilities Versions 2.1 and lower of the "theme-editor" plugin are affected by multiple vulnerabilities such as CSRF, insufficient permission checking, arbitrary file upload and the ability to interact with folders/files on the server in most ways you can imagine. These vulnerabilities (aside from CSRF) require access to any account, regardless of its role.
- Affected versions
-
max 2.2.
- Status
-
vulnerable
Aug 02, 2026
Theme Editor # CVE-2025-14469
- CVE, Research URL
- Home page URL
- Application
- Date
- Aug 01, 2026
- Research Description
- The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1. This is due to missing nonce validation on the ms_update AJAX action. This makes it possible for unauthenticated attackers to modify child theme CSS styles via a forged request granted they can trick an administrator into performing an action such as clicking on a link.
- Affected versions
-
max 3.2.
- Status
-
vulnerable