What is CVE-2025-14469?
A critical Cross-Site Request Forgery (CSRF) vulnerability exists in the Theme Editor plugin for WordPress up to version 3.1. Missing nonce validation on the `ms_update` AJAX action allows unauthenticated attackers to modify child theme CSS styles via a forged request. Immediate plugin update or temporary deactivation is recommended.
Azərbaycanca: WordPress üçün Theme Editor plaqinində kritik Cross-Site Request Forgery (CSRF) zəifliyi aşkarlanıb. Plaqinin 3.1-ə qədər bütün versiyalarında `ms_update` AJAX funksiyasında nonce doğrulamasının olmaması səbəbindən autentifikasiya olunmamış hücumçular saxta sorğu vasitəsilə alt tema CSS stillərini dəyişə bilər. Plaqinini dərhal ən son versiyaya yeniləmək və ya müvəqqəti olaraq deaktiv etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-352
FAQ2
Which versions of the Theme Editor plugin are affected by CVE-2025-14469?
The vulnerability affects all versions of the Theme Editor plugin up to 3.1.
What can an attacker achieve by exploiting CVE-2025-14469?
An unauthenticated attacker can modify child theme CSS styles via a forged request.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.