Software intelligence
Important: Theme Editor appearing in this catalog does not mean your website is affected. Exposure depends on your installed version. How SiteRespond intelligence works
Tracked advisories
7
Latest advisory
31 July 2026
CISA KEV matches
0
In this WordPress feed
WordPress slug
theme-editor
Plugin
This catalog lists 7 known advisories affecting Theme Editor. The most recent was published on 31 July 2026. If you use this software, compare your installed version against the affected ranges on each advisory and update to a fixed release outside those ranges. SiteRespond Defence checks your actual installed version when the plugin is connected — listing here does not by itself mean your site is vulnerable.
Theme Editor <= 3.1 - Cross-Site Request Forgery to CSS Modification
May trick authenticated users into performing unintended actions.
Published 31 July 2026
Theme Editor <= 3.2 - Cross-Site Request Forgery
May trick authenticated users into performing unintended actions.
Published 14 February 2026
Theme Editor <= 3.0 - Cross-Site Request Forgery to Remote Code Execution
May allow attackers to run arbitrary code on the server if exploited.
Published 17 October 2025
Known Theme Editor advisories published by month.
CVE-2025-14469 · Published 31 July 2026
Affected versions: ≤ 3.1
CVE-2026-39640 · Published 14 February 2026
Affected versions: ≤ 3.2
CVE-2025-9890 · Published 17 October 2025
Affected versions: ≤ 3.0
CVE-2022-2440 · Published 28 August 2024
Affected versions: ≤ 2.8
CVE-2023-6091 · Published 20 November 2023
Affected versions: ≤ 2.7.1
CVE-2021-24154 · Published 13 February 2021
Affected versions: ≤ 2.5
No CVE assigned · Published 30 September 2019
Affected versions: < 2.2
SiteRespond Defence matches your installed Theme Editor version against this catalog when the Defence plugin is connected to your WordPress site.