Vulnerability Description
Multiple plugins and/or themes for WordPress by LiquidThemes are vulnerable to unauthorized access due to a missing capability check on the liquid_reset_wordpress_before AJAX in various versions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to deactivate all of a site's plugins. While we escalated this to Envato after not being able to establish contact, it appears the developer added a nonce check, however that is not sufficient protection as the nonce is exposed to all users with access to the dashboard.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://themeforest.net/user/liquidthemes
- https://www.wordfence.com/threat-intel/vulnerabilities/id/0099c700-e1af-4d97-a51
FAQ
What is CVE-2025-0951?
CVE-2025-0951 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Multiple plugins and/or themes for WordPress by LiquidThemes are vulnerable to unauthorized access due to a missing capability check on the liquid_reset_wordpress_before AJAX in various versions. This...
How severe is CVE-2025-0951?
CVE-2025-0951 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-0951?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.