
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14392 is a missing authorization vulnerability in the Simple Theme Changer plugin for WordPress, allowing authenticated attackers with subscriber-level access or above to modify plugin settings without proper capability checks. It affects all versions of the plugin up to and including version 1.0, developed by darendev. The vulnerability was published on December 12, 2025, and assigned by Wordfence. It carries a CVSS v3.1 base score of 4.3 (Medium) (Wordfence, Red Hat CVE).
The root cause is a missing capability check (CWE-862) on three AJAX action handlers: user_theme_admin, display_method_admin, and set_change_theme_button_name, as implemented in class_theme_changer.php. Because WordPress does not enforce administrator-level permissions on these actions, any authenticated user — including those with the lowest default role (subscriber) — can invoke them over the network without additional interaction. The vulnerable code is visible in the plugin's source repository at line 262 of the tagged release (Wordfence, Plugin Source).
Successful exploitation allows a low-privileged authenticated attacker to arbitrarily modify the plugin's theme selection, display method, and button name settings on the affected WordPress site. The primary impact is an integrity violation — unauthorized changes to site appearance — with no direct confidentiality or availability impact. In practice, this could be leveraged to alter the site's visual presentation for social engineering or phishing purposes, or to disrupt the intended user experience (Wordfence).
No public exploit code or active in-the-wild exploitation has been reported for CVE-2025-14392. The EPSS score is approximately 0.026% (0.000260), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires a valid authenticated session at subscriber level or above, limiting the attack surface to sites with open user registration or compromised accounts (Wordfence).
/wp-content/plugins/simple-theme-changer/)./wp-admin/admin-ajax.php) with the action parameter set to one of the vulnerable handlers, e.g., action=user_theme_admin, action=display_method_admin, or action=set_change_theme_button_name, along with the desired setting values./wp-admin/admin-ajax.php with action=user_theme_admin, action=display_method_admin, or action=set_change_theme_button_name from non-administrative user accounts.wp_options table entries related to simple-theme-changer).Site administrators should deactivate and remove the Simple Theme Changer plugin (version ≤1.0) until a patched version is released by the vendor (darendev). No patched version has been publicly announced as of the disclosure date. As a workaround, disabling open user registration or restricting subscriber-level access can reduce the attack surface. Monitoring admin-ajax requests for the affected action names can help detect exploitation attempts (Wordfence).
The vulnerability was discovered and reported by Wordfence, which published the advisory through its threat intelligence platform. Coverage has been limited to automated vulnerability aggregators and a brief technical post on infinitsec.net. No significant vendor statements, notable researcher commentary, or broad media coverage has been observed for this low-severity issue (Wordfence).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."