A vulnerability classified as problematic was found in Theme Editor Plugin up to 3.1 on WordPress. This impacts the function ms_update. Such manipulation leads to cross-site request forgery.

This vulnerability is documented as CVE-2025-14469. The attack can be executed remotely. There is not any exploit available.