PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-9266 themegrill CVE debrief

The Accelerate theme for WordPress has a vulnerability allowing unauthorized data modification due to a missing capability check on the enqueue_scripts() function in versions up to 1.5.3. Authenticated attackers with Subscriber-level access can install and activate the ThemeGrill Demo Importer plugin. This vulnerability affects WordPress installations with the Accelerate theme, particularly those with Subscriber-level access or higher. The vulnerability allows for potential data modification and other security issues. Defenders should verify the Accelerate theme version and review user roles and permissions to prevent unauthorized data modification.

Vendor
themegrill
Product
Accelerate
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-06
Original CVE updated
2026-08-06
Advisory published
2026-08-06
Advisory updated
2026-08-06

Who should care

WordPress users with the Accelerate theme installed, particularly those with Subscriber-level access or higher, should be aware of this vulnerability and take steps to mitigate it. This includes updating to version 1.5.4 or later, restricting access to the enqueue_scripts() function, and monitoring for suspicious plugin installations. Additionally, users should review and adjust user roles and permissions to prevent unauthorized data modification.

Technical summary

The Accelerate theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the enqueue_scripts() function in all versions up to, and including, 1.5.3. This allows authenticated attackers with Subscriber-level access and above to install and activate the ThemeGrill Demo Importer plugin, potentially leading to data modification and other security issues.

Defensive priority

Medium priority due to CVSS score of 4.3 and potential for data modification.

Recommended defensive actions

  • Verify the Accelerate theme version and update to 1.5.4 or later.
  • Restrict access to the enqueue_scripts() function.
  • Monitor for suspicious plugin installations.
  • Review and adjust user roles and permissions.
  • Implement additional security measures to prevent unauthorized data modification.
  • Conduct a thorough review of the affected system to ensure no unauthorized changes have been made.
  • Track exceptions and retest remediated assets to ensure the vulnerability has been fully mitigated.

Evidence notes

The evidence from the NVD and Wordfence indicates a vulnerability in the Accelerate theme for WordPress, allowing unauthorized modification of data due to a missing capability check on the enqueue_scripts() function. This vulnerability affects versions up to, and including, 1.5.3 and allows authenticated attackers with Subscriber-level access and above to install and activate the ThemeGrill Demo Importer plugin. Defenders should verify the Accelerate theme version, review user roles and permissions, and monitor for suspicious plugin installations.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T12:16:26.680Z and has not been modified since then.