CVE-2025-0951: Liquidthemes Ai Hub - Startup & Technology WordPress Theme

Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.

Multiple plugins and/or themes for WordPress by LiquidThemes are vulnerable to unauthorized access due to a missing capability check on the liquid_reset_wordpress_before AJAX in various versions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to deactivate all of a site's plugins. While we escalated this to Envato after not being able to establish contact, it appears the developer added a nonce check, however that is not sufficient protection as the nonce is exposed to all users with access to the dashboard.

Affected products

  • Liquidthemes Ai Hub - Startup & Technology WordPress Theme: version 0 only
  • Liquidthemes Archub - Architecture And Interior Design WordPress Theme: version 0 only
  • Liquidthemes Hub - Responsive Multi-Purpose WordPress Theme: version 0 only

Published 2025-08-28. Last modified 2026-06-17.