Known vulnerabilities in Theme Editor
Theme Editor allows you to edit theme files, create folder, upload files and remove any file and folder in themes and plugins.
7Reported vulnerabilities
8.8Highest CVSS score
3.2Latest version
50,000+Active installs
What to do now
Update Theme Editor to 3.2 or later.
6 of these have a fixed version available. Updating resolves them.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2025-9890 | High | 0.4% | 0 to 3.0 (inclusive) | 3.1 |
October 18, 2025 |
| WF-98286172-99b0-43d6-9876-972e270aa19f | High | — | Before 2.2 | 2.2 |
September 30, 2019 |
| CVE-2022-2440 | High | 0.7% | Before 2.9 | 2.9 |
August 29, 2024 |
| CVE-2023-6091 | High | 0.6% | 2.7.1 and earlier | 2.8 |
November 20, 2023 |
| CVE-2021-24154 | Medium | 1.1% | Before 2.6 | 2.6 |
April 5, 2021 |
| CVE-2025-14469 | Medium | 0.1% | 0 to 3.1 (inclusive) | 3.2 |
August 1, 2026 |
| CVE-2026-39640 | Medium | 0.1% | 3.2 and earlier | — | February 14, 2026 |