← back to popular plugins
wordfence / plugin · theme-editor

Theme Editor

theme-editor
total installs
50,000
total vulns
2
critical
0
high
1
medium
1
low
0
latest vuln
patched
1
unpatched
1
avg time to patch
vulnerabilities (2)
Theme Editor <= 3.2 - Cross-Site Request Forgery
medium ✕ unpatched
cvss score 4.3
cwe CWE-352: Cross-Site Request Forgery (CSRF)
published Feb 14, 2026
The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Theme Editor <= 3.0 - Cross-Site Request Forgery to Remote Code Execution
high ✓ patched
cvss score 8.8
cwe CWE-352: Cross-Site Request Forgery (CSRF)
published Oct 17, 2025
The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0. This is due to missing or incorrect nonce validation on the 'theme_editor_theme' page. This makes it possible for unauthenticated attackers to achieve remote code execution via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.