THREAT OPS › Threat News › [NVD] CVE-2025-14469 (MEDIUM 4.3) — The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1. This is due to missing nonce validation on the ms_update AJAX action. This makes it possible for unauthenticated attackers to modify child theme CSS styles
[NVD] CVE-2025-14469 (MEDIUM 4.3) — The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1. This is due to missing nonce validation on the ms_update AJAX action. This makes it possible for unauthenticated attackers to modify child theme CSS styles
CVE-2025-14469 CVSS: 4.3 MEDIUM Published: 2026-08-01T08:16:29.167
The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1. This is due to missing nonce validation on the ms_update AJAX action. This makes it possible for unauthenticated attackers to modify child theme CSS styles via a forged request granted they can trick an admi
Indicators of compromise
- CVE-2025-14469cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-14469