Theme Editor

Information

Software Type Plugin
Software Slug theme-editor (view on wordpress.org)
Software Status Active
Software Author mndpsingh287
Software Website themeeditor.pro
Software Downloads 931,718
Software Active Installs 50,000
Software Record Last Updated August 17, 2026

7 Vulnerabilities

Title Status CVE ID CVSS Researchers Date
Theme Editor <= 3.1 - Cross-Site Request Forgery to CSS Modification Patched CVE-2025-14469 4.3 Nabil Irawan July 31, 2026
Theme Editor <= 3.2 - Cross-Site Request Forgery Unpatched CVE-2026-39640 4.3 hhhai February 14, 2026
Theme Editor <= 3.0 - Cross-Site Request Forgery to Remote Code Execution Patched CVE-2025-9890 8.8 Jonas Benjamin Friedli October 17, 2025
Theme Editor <= 2.8 - Authenticated (Admin+) PHAR Deserialization Patched CVE-2022-2440 7.2 Rasoul Jahanshahi August 28, 2024
Theme Editor <= 2.7.1 - Authenticated (Administrator+) Arbitrary File Upload Patched CVE-2023-6091 7.2 Dateoljo of BoB 12th November 20, 2023
Theme Editor <= 2.5 - Authenticated Arbitrary File Download Patched CVE-2021-24154 4.9 Nguyen Van Khanh February 13, 2021
Theme Editor <= 2.1 - Cross-Site Request Forgery Patched 8.8 September 30, 2019

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation