CVE-2025-0951: Liquidthemes Ai Hub - Startup & Technology WordPress Theme
Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.
Multiple plugins and/or themes for WordPress by LiquidThemes are vulnerable to unauthorized access due to a missing capability check on the liquid_reset_wordpress_before AJAX in various versions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to deactivate all of a site's plugins. While we escalated this to Envato after not being able to establish contact, it appears the developer added a nonce check, however that is not sufficient protection as the nonce is exposed to all users with access to the dashboard.
Affected products
- Liquidthemes Ai Hub - Startup & Technology WordPress Theme: version 0 only
- Liquidthemes Archub - Architecture And Interior Design WordPress Theme: version 0 only
- Liquidthemes Hub - Responsive Multi-Purpose WordPress Theme: version 0 only
Published 2025-08-28. Last modified 2026-06-17.