THREATOPS
THREAT OPSThreat News › [NVD] CVE-2025-14469 (MEDIUM 4.3) — The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1. This is due to missing nonce validation on the ms_update AJAX action. This makes it possible for unauthenticated attackers to modify child theme CSS styles

[NVD] CVE-2025-14469 (MEDIUM 4.3) — The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1. This is due to missing nonce validation on the ms_update AJAX action. This makes it possible for unauthenticated attackers to modify child theme CSS styles

mednvdPublished 2026-08-01

CVE-2025-14469 CVSS: 4.3 MEDIUM Published: 2026-08-01T08:16:29.167

The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1. This is due to missing nonce validation on the ms_update AJAX action. This makes it possible for unauthenticated attackers to modify child theme CSS styles via a forged request granted they can trick an admi

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-14469