PT-2025-46282 · WordPress · Theme Editor

Kenneth Dunn

·

Published

2025-11-11

·

Updated

2025-11-11

·

CVE-2025-12637

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Elastic Theme Editor plugin for WordPress versions up to and including 0.0.3
Description The Elastic Theme Editor plugin for WordPress is susceptible to arbitrary file uploads. This is due to a dynamic code generation feature within the process theme function. Authenticated attackers with Subscriber-level access or higher can upload arbitrary files to the affected server, potentially leading to remote code execution.
Recommendations Update the Elastic Theme Editor plugin to a version beyond 0.0.3.

Fix

RCE

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-12637

Affected Products

Theme Editor