PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-9266 themegrill CVE debrief

The Accelerate theme for WordPress has a vulnerability allowing unauthorized data modification due to a missing capability check on the enqueue_scripts() function in versions up to 1.5.3. Authenticated attackers with Subscriber-level access can install and activate the ThemeGrill Demo Importer plugin. This vulnerability affects WordPress installations with the Accelerate theme, particularly those with Subscriber-level access or higher. The vulnerability allows for potential data modification and other security issues. Defenders should verify the Accelerate theme version and review user roles and permissions to prevent unauthorized data modification.

Vendor
themegrill
Product
Accelerate
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-06
Original CVE updated
2026-08-06
Advisory published
2026-08-06
Advisory updated
2026-08-06

Who should care

WordPress users with the Accelerate theme installed, particularly those with Subscriber-level access or higher, should be aware of this vulnerability and take steps to mitigate it. This includes updating to version 1.5.4 or later, restricting access to the enqueue_scripts() function, and monitoring for suspicious plugin installations. Additionally, users should review and adjust user roles and permissions to prevent unauthorized data modification.

Technical summary

The Accelerate theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the enqueue_scripts() function in all versions up to, and including, 1.5.3. This allows authenticated attackers with Subscriber-level access and above to install and activate the ThemeGrill Demo Importer plugin, potentially leading to data modification and other security issues.

Defensive priority

Medium priority due to CVSS score of 4.3 and potential for data modification.

Recommended defensive actions

  • Verify the Accelerate theme version and update to 1.5.4 or later.
  • Restrict access to the enqueue_scripts() function.
  • Monitor for suspicious plugin installations.
  • Review and adjust user roles and permissions.
  • Implement additional security measures to prevent unauthorized data modification.
  • Conduct a thorough review of the affected system to ensure no unauthorized changes have been made.
  • Track exceptions and retest remediated assets to ensure the vulnerability has been fully mitigated.

Evidence notes

The evidence from the NVD and Wordfence indicates a vulnerability in the Accelerate theme for WordPress, allowing unauthorized modification of data due to a missing capability check on the enqueue_scripts() function. This vulnerability affects versions up to, and including, 1.5.3 and allows authenticated attackers with Subscriber-level access and above to install and activate the ThemeGrill Demo Importer plugin. Defenders should verify the Accelerate theme version, review user roles and permissions, and monitor for suspicious plugin installations.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-9266 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-9266

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-9266 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-9266

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://themes.trac.wordpress.org/changeset/283564/accelerate/1.5.4/inc/admin/class-accelerate-admin.php

    [email protected]

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.