A vulnerability classified as problematic was found in Theme Editor Plugin up to 3.1 on WordPress. This impacts the function
ms_update. Such manipulation leads to cross-site request forgery.
This vulnerability is documented as CVE-2025-14469. The attack can be executed remotely. There is not any exploit available.