Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-25959 | Multiple plugins and/or themes for WordPress by LiquidThemes are vulnerable to unauthorized access due to a missing capability check on the liquid_reset_wordpress_before AJAX in various versions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to deactivate all of a site's plugins. While we escalated this to Envato after not being able to establish contact, it appears the developer added a nonce check, however that is not sufficient protection as the nonce is exposed to all users with access to the dashboard. |
Fri, 27 Feb 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 28 Aug 2025 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Liquidthemes
Liquidthemes ai Hub Liquidthemes archub Liquidthemes hub Wordpress Wordpress wordpress |
|
| Vendors & Products |
Liquidthemes
Liquidthemes ai Hub Liquidthemes archub Liquidthemes hub Wordpress Wordpress wordpress |
Thu, 28 Aug 2025 04:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Multiple plugins and/or themes for WordPress by LiquidThemes are vulnerable to unauthorized access due to a missing capability check on the liquid_reset_wordpress_before AJAX in various versions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to deactivate all of a site's plugins. While we escalated this to Envato after not being able to establish contact, it appears the developer added a nonce check, however that is not sufficient protection as the nonce is exposed to all users with access to the dashboard. | |
| Title | LiquidThemes Themes <= Various Versions - Missing Authorization to Authenticated (Subscriber+) All Plugins Deactivated | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:32:21.073Z
Reserved: 2025-01-31T19:34:34.392Z
Link: CVE-2025-0951
Updated: 2025-08-28T14:18:19.009Z
Status : Deferred
Published: 2025-08-28T04:15:56.903
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-0951
No data.
OpenCVE Enrichment
Updated: 2026-04-28T11:00:14Z
EUVD