What is CVE-2025-9266?
The Accelerate theme for WordPress is vulnerable to unauthorized data modification due to a missing capability check in the `enqueue_scripts()` function in versions up to and including 1.5.3. This vulnerability affects authenticated attackers with Subscriber-level access and above. Immediate theme update to the latest version is recommended to mitigate the risk.
Azərbaycanca: WordPress üçün Accelerate teması, 1.5.3 versiyasına qədər olan bütün versiyalarda `enqueue_scripts()` funksiyasında çatışmayan icazə yoxlaması səbəbindən məlumatların icazəsiz dəyişdirilməsinə qarşı zəifdir. Bu zəiflik, Subscriber səviyyəsində və daha yuxarı icazələrə malik autentifikasiya olunmuş hücumçulara təsir göstərə bilər. Təhlükəsizlik üçün temanın dərhal ən son versiyaya yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
In which function of the WordPress Accelerate theme was the CVE-2025-9266 vulnerability discovered?
The vulnerability occurs due to a missing capability check in the `enqueue_scripts()` function.
What is the minimum permission level required for an attacker to exploit this vulnerability?
The attacker must be an authenticated user with Subscriber-level access or above.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.