PatchSiren cyber security CVE debrief
CVE-2025-9266 themegrill CVE debrief
The Accelerate theme for WordPress has a vulnerability allowing unauthorized data modification due to a missing capability check on the enqueue_scripts() function in versions up to 1.5.3. Authenticated attackers with Subscriber-level access can install and activate the ThemeGrill Demo Importer plugin. This vulnerability affects WordPress installations with the Accelerate theme, particularly those with Subscriber-level access or higher. The vulnerability allows for potential data modification and other security issues. Defenders should verify the Accelerate theme version and review user roles and permissions to prevent unauthorized data modification.
- Vendor
- themegrill
- Product
- Accelerate
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-06
- Original CVE updated
- 2026-08-06
- Advisory published
- 2026-08-06
- Advisory updated
- 2026-08-06
Who should care
WordPress users with the Accelerate theme installed, particularly those with Subscriber-level access or higher, should be aware of this vulnerability and take steps to mitigate it. This includes updating to version 1.5.4 or later, restricting access to the enqueue_scripts() function, and monitoring for suspicious plugin installations. Additionally, users should review and adjust user roles and permissions to prevent unauthorized data modification.
Technical summary
The Accelerate theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the enqueue_scripts() function in all versions up to, and including, 1.5.3. This allows authenticated attackers with Subscriber-level access and above to install and activate the ThemeGrill Demo Importer plugin, potentially leading to data modification and other security issues.
Defensive priority
Medium priority due to CVSS score of 4.3 and potential for data modification.
Recommended defensive actions
- Verify the Accelerate theme version and update to 1.5.4 or later.
- Restrict access to the enqueue_scripts() function.
- Monitor for suspicious plugin installations.
- Review and adjust user roles and permissions.
- Implement additional security measures to prevent unauthorized data modification.
- Conduct a thorough review of the affected system to ensure no unauthorized changes have been made.
- Track exceptions and retest remediated assets to ensure the vulnerability has been fully mitigated.
Evidence notes
The evidence from the NVD and Wordfence indicates a vulnerability in the Accelerate theme for WordPress, allowing unauthorized modification of data due to a missing capability check on the enqueue_scripts() function. This vulnerability affects versions up to, and including, 1.5.3 and allows authenticated attackers with Subscriber-level access and above to install and activate the ThemeGrill Demo Importer plugin. Defenders should verify the Accelerate theme version, review user roles and permissions, and monitor for suspicious plugin installations.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T12:16:26.680Z and has not been modified since then.