WPIntell

Source evidence

Security issue

Theme Editor · support · 2026-05-09T08:26:00+00:00

mixedsentiment
highseverity
0.82relevance
8replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

5 / 24 rows with source links

20.8% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

19 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
Rainer R. unresolved
Hello, Wordfence shows security issue. https://mallorca-broker.com Worpress 6.9.4 , Theme editor 3.2 Details: To protect your site from this vulnerability, the safest option is to deactivate and completely remove “Theme Editor” until a patched version is available. https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/theme-editor/theme-editor-32-cross-site-request-forgery Hope you can solve the security problem. Regards Rainer The page I need help with: [ log in to see the link] Yes, I read an article posted by WordFence about this vulnerability a couple of months ago . Is this vulnerability going to be patched in the near future? If not, I’ll need to delete the Theme Editor plugin. Best, Matthew Hi @rainer-r @matthewjasonklodt , Our team has fixed this vulnerability in Theme Editor plugin. The fix will be shared on the live stage soon. Thanks for the alert. If you have any questions about the fix, please feel free to ask. Regards, WP Theme Editor Support. Good news 👍 Thanks for your update, @emma1991 . Do you have any ETA regarding the release of this plugin update? This vulnerability has been listed on WordFence’s Intelligence reports for several months now, so I need to make a decision whether or not to disable/remove the ‘Theme Editor’ plugin, at least for the time being, until the security fix has been uploaded. Thanks. Best, Matthew This reply was modified 3 weeks, 2 days ago by Matthew Klodt . Reason: Wanted to include a link to WordFence's report to clarify the issue that I'm referring to Hi @matthewjasonklodt , We have fixed this issue – please update the plugin to the latest version and check. Let us know if you need any further help! Thanks, Theme Editor Support Team @emma1991 , where can we find the updated version? There is no update showing in my WordPress admin and the previous plugin version is still listed on the WordPress.org plugin repository. This reply was modified 1 week, 4 days ago by Matthew Klodt . Hi @matthewjasonklodt , Thank you for your patience! We have a patch ready for you to test. Please download it using the link below and install it manually by going to Plugins → Add New → Upload Plugin : 📎 theme-editor-v-3.3.zip Please check if this resolves the issue and let us know how it goes. We’ll push the official update to the WordPress.org repository shortly. Thanks, Theme Editor Support Team @emma1991 , That seems to have fixed the security warning in WordFence on my personal WordPress website. I’m not seeing any PHP errors or warnings either related to the ‘Theme Editor’ plugin updator, so it looks good. However, I don’t want to install it on my client’s website until you’re finished testing it and the new version has been uploaded to the WordPress pluginr repository. Next time if you need me to do any plugin testing, you’ll need to hire me for my freelance WordPress development services. 😉

Comments

8 shown
Matthew Klodt 2026-05-10T05:14:00+00:00

Yes, I read an article posted by WordFence about this vulnerability a couple of months ago . Is this vulnerability going to be patched in the near future? If not, I’ll need to delete the Theme Editor plugin. Best, Matthew

Emma (Support Executive) 2026-05-15T07:14:00+00:00

Hi @rainer-r @matthewjasonklodt , Our team has fixed this vulnerability in Theme Editor plugin. The fix will be shared on the live stage soon. Thanks for the alert. If you have any questions about the fix, please feel free to ask. Regards, WP Theme Editor Support.

Rainer R. 2026-05-15T10:00:00+00:00

Good news 👍

Matthew Klodt 2026-06-07T22:10:00+00:00

Thanks for your update, @emma1991 . Do you have any ETA regarding the release of this plugin update? This vulnerability has been listed on WordFence’s Intelligence reports for several months now, so I need to make a decision whether or not to disable/remove the ‘Theme Editor’ plugin, at least for the time being, until the security fix has been uploaded. Thanks. Best, Matthew This reply was modified 3 weeks, 2 days ago by Matthew Klodt . Reason: Wanted to include a link to WordFence's report to clarify the issue that I'm referring to

Emma (Support Executive) 2026-06-10T10:56:00+00:00

Hi @matthewjasonklodt , We have fixed this issue – please update the plugin to the latest version and check. Let us know if you need any further help! Thanks, Theme Editor Support Team

Matthew Klodt 2026-06-20T02:29:00+00:00

@emma1991 , where can we find the updated version? There is no update showing in my WordPress admin and the previous plugin version is still listed on the WordPress.org plugin repository. This reply was modified 1 week, 4 days ago by Matthew Klodt .

Emma (Support Executive) 2026-06-22T10:38:00+00:00

Hi @matthewjasonklodt , Thank you for your patience! We have a patch ready for you to test. Please download it using the link below and install it manually by going to Plugins → Add New → Upload Plugin : 📎 theme-editor-v-3.3.zip Please check if this resolves the issue and let us know how it goes. We’ll push the official update to the WordPress.org repository shortly. Thanks, Theme Editor Support Team

Matthew Klodt 2026-06-24T03:29:00+00:00

@emma1991 , That seems to have fixed the security warning in WordFence on my personal WordPress website. I’m not seeing any PHP errors or warnings either related to the ‘Theme Editor’ plugin updator, so it looks good. However, I don’t want to install it on my client’s website until you’re finished testing it and the new version has been uploaded to the WordPress pluginr repository. Next time if you need me to do any plugin testing, you’ll need to hire me for my freelance WordPress development services. 😉