{"id":380851,"date":"2026-10-08T22:22:18","date_gmt":"2026-10-08T22:22:18","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/editor-theme-access-for-kadence\/"},"modified":"2026-10-08T22:31:18","modified_gmt":"2026-10-08T22:31:18","slug":"jjcm-editor-theme-access-for-kadence","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/jjcm-editor-theme-access-for-kadence\/","author":23574459,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"2.1.2","stable_tag":"2.1.2","tested":"7.1.3","requires":"5.8","requires_php":"7.4","requires_plugins":null,"header_name":"JJCM Editor Theme Access for Kadence","header_author":"Jos\u00e9","header_description":"Gives the \"editor\" role full access to the Kadence theme's Customizer (Header, Footer, Colors & Fonts, General, Posts\/Pages Layout, etc.), which Kadence only fully displays to users with manage_options. The elevation only applies when Kadence is the active theme, only during verified (nonce-checked) Customizer requests, and is never written to the database.","assets_banners_color":"","last_updated":"2026-10-08 22:31:18","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/github.com\/jjcm1912\/editor-theme-access-for-kadence","header_author_uri":"https:\/\/github.com\/jjcm1912","rating":0,"author_block_rating":0,"active_installs":0,"downloads":67,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"2.1.2":{"tag":"2.1.2","author":"jjcm1962","date":"2026-10-08 22:31:18","revision":3735643}},"upgrade_notice":{"2.1.0":"<p>Behavior change: starting with this version, Editors receive\nmanage_options (not just edit_theme_options), but only during\nverified Customizer\/Kadence requests. Review the FAQ before updating\non a production site.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3735638,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3735638,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256},"icon.svg":{"filename":"icon.svg","revision":3735638,"resolution":false,"location":"assets","locale":false}},"assets_banners":[],"assets_blueprints":{},"all_blocks":[],"tagged_versions":["2.1.2"],"block_files":[],"assets_screenshots":[],"screenshots":[]},"plugin_section":[],"plugin_tags":[1913,2768,1332,190017,10192],"plugin_category":[43,46],"plugin_contributors":[285178],"plugin_business_model":[],"class_list":["post-380851","plugin","type-plugin","status-publish","hentry","plugin_tags-capabilities","plugin_tags-customizer","plugin_tags-editor","plugin_tags-kadence","plugin_tags-theme-options","plugin_category-customization","plugin_category-editor-and-writing","plugin_contributors-jjcm1962","plugin_committers-jjcm1962"],"banners":[],"icons":{"svg":"https:\/\/ps.w.org\/jjcm-editor-theme-access-for-kadence\/assets\/icon.svg?rev=3735638","icon":"https:\/\/ps.w.org\/jjcm-editor-theme-access-for-kadence\/assets\/icon.svg?rev=3735638","icon_2x":false,"generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p>The Kadence theme uses its own internal capability check to decide\nwhether to display its own Customizer panels (Header, Footer, Colors\n&amp; Fonts, General, Posts\/Pages Layout, Homepage Settings, etc.). In\npractice, that check is only satisfied by <code>manage_options<\/code> \u2014 the\nstandard <code>edit_theme_options<\/code> capability, which the Editor role\nnormally lacks, is not enough: an Editor with only\n    edit_theme_options still sees just the native WordPress panels\n(Site Identity, Menus, Widgets, Additional CSS), not Kadence's own\npanels.<\/p>\n\n<p>This plugin solves that by granting <code>manage_options<\/code> to Editor users,\nbut in a tightly scoped way:<\/p>\n\n<ol>\n<li><strong>Only when the active theme is actually Kadence<\/strong> (or a Kadence\nchild theme). The plugin can stay installed and active on any\nWordPress site \u2014 it does nothing on sites using a different theme.\nThere is no need to deactivate it when switching themes, or to\ninstall a different variant for other themes.<\/li>\n<li><strong>Only at runtime.<\/strong> The capability is never written to the role\nor to any database option \u2014 it is returned by the <code>user_has_cap<\/code>\nfilter only for the duration of the current HTTP request.<\/li>\n<li><strong>Only during verified Customizer requests<\/strong>, with a nonce check\non every possible path: native Customizer preview, AJAX save\nrequests, and REST requests to <code>\/wp\/v2\/settings<\/code> or\n   \/wp\/v2\/themes. The mere presence of a URL parameter is never\nenough on its own \u2014 this prevents an Editor from obtaining\n   manage_options on other wp-admin pages simply by tampering with\nthe query string.<\/li>\n<\/ol>\n\n<p>Outside of those conditions, the Editor has <code>manage_options<\/code> nowhere\nelse: they remain without access to Plugins, Users, or any other page\nthat depends on that capability.<\/p>\n\n<p><strong>Nothing is written to the database<\/strong><\/p>\n\n<ul>\n<li>There is no <code>add_cap()<\/code> call on the <code>WP_Role<\/code> object, in any\nactivation, deactivation, or <code>admin_init<\/code> hook.<\/li>\n<li>There is no <code>register_setting<\/code>, <code>update_option<\/code>, or\n  update_user_meta anywhere in the plugin.<\/li>\n<li>Deactivating the plugin immediately restores native WordPress\nbehavior for all Editors; uninstalling leaves no residue in the\ndatabase.<\/li>\n<\/ul>\n\n<p><strong>Extensibility<\/strong><\/p>\n\n<p>By default, the elevation applies to all Editors (within the\nconditions above). To restrict it to specific users, use the\n    etak_grant_theme_access filter in a must-use plugin or in the\ntheme's <code>functions.php<\/code> \u2014 without modifying this plugin:<\/p>\n\n<pre><code>add_filter( 'etak_grant_theme_access', function ( $grant, $user ) {\n    return in_array( $user-&gt;ID, array( 5, 12 ), true );\n}, 10, 2 );\n<\/code><\/pre>\n\n<p>You can also adjust the AJAX actions and REST routes recognized as\nCustomizer\/Kadence context through the <code>etak_customizer_ajax_actions<\/code>\nand <code>etak_customizer_rest_routes<\/code> filters \u2014 useful if your site has\nadditional Kadence-related integrations using different actions or\nroutes than the defaults.<\/p>\n\n<p>If your Kadence installation (or a variant of it) uses a different\ntheme slug, adjust it with <code>etak_kadence_theme_slugs<\/code>:<\/p>\n\n<pre><code>add_filter( 'etak_kadence_theme_slugs', function ( $slugs ) {\n    return array_merge( $slugs, array( 'my-kadence-slug' ) );\n} );\n<\/code><\/pre>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>editor-theme-access-for-kadence<\/code> folder to the\n   \/wp-content\/plugins\/ directory, or install the plugin directly\nfrom the \"Plugins\" screen in WordPress.<\/li>\n<li>Activate the plugin through the \"Plugins\" menu in WordPress.<\/li>\n<li>No further configuration is needed. Users with the Editor role can\nnow open and save every Kadence Customizer panel.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"why%20does%20the%20plugin%20grant%20manage_options%2C%20instead%20of%20just%20edit_theme_options%3F\"><h3>Why does the plugin grant manage_options, instead of just edit_theme_options?<\/h3><\/dt>\n<dd><p>Because Kadence, for its own panels (Header, Footer, Colors &amp; Fonts,\nGeneral, Posts\/Pages Layout, Homepage Settings), internally checks a\ncapability that only <code>manage_options<\/code> satisfies. <code>edit_theme_options<\/code>\nalone only reveals the native WordPress panels (Site Identity, Menus,\nWidgets, Additional CSS).<\/p><\/dd>\n<dt id=\"isn%27t%20this%20dangerous%20%E2%80%94%20doesn%27t%20an%20editor%20become%20almost%20an%20administrator%3F\"><h3>Isn't this dangerous \u2014 doesn't an Editor become almost an Administrator?<\/h3><\/dt>\n<dd><p>The elevation only exists during verified (nonce-checked) Customizer\nrequests \u2014 never persistently or globally. An Editor does not gain\n    manage_options by visiting Plugins, Users, or any other wp-admin\npage; only inside the Customizer screen itself and the requests it\ngenerates. That said, it is still a real elevation: an Editor with\nCustomizer access can change any setting that lives there (including,\nfor example, \"Additional CSS\", which accepts arbitrary CSS, or panels\nfrom other plugins that also depend on <code>manage_options<\/code> and appear in\nthe Customizer). Weigh this trade-off before activating the plugin on\na site with multiple Editors.<\/p><\/dd>\n<dt id=\"do%20i%20need%20to%20deactivate%20the%20plugin%20if%20i%20switch%20themes%3F\"><h3>Do I need to deactivate the plugin if I switch themes?<\/h3><\/dt>\n<dd><p>No. The plugin checks, on every request, whether the active theme\n(<code>get_template()<\/code>) is <code>kadence<\/code>; if it isn't, it does nothing at all.\nYou can leave it always active, even on sites that don't use Kadence,\nor switch themes without worrying about deactivating it first.<\/p><\/dd>\n<dt id=\"is%20the%20permission%20recorded%20in%20the%20database%3F\"><h3>Is the permission recorded in the database?<\/h3><\/dt>\n<dd><p>No, under any circumstance. It is recalculated on every request\nthrough the <code>user_has_cap<\/code> filter.<\/p><\/dd>\n<dt id=\"can%20i%20restrict%20this%20to%20a%20specific%20editor%3F\"><h3>Can I restrict this to a specific Editor?<\/h3><\/dt>\n<dd><p>Yes, via the <code>etak_grant_theme_access<\/code> filter (see the Description\nsection) in a must-use plugin or the theme's <code>functions.php<\/code> \u2014 no\nneed to modify this plugin.<\/p><\/dd>\n<dt id=\"is%20this%20plugin%20official%2C%20or%20affiliated%20with%20kadence%20wp%3F\"><h3>Is this plugin official, or affiliated with Kadence WP?<\/h3><\/dt>\n<dd><p>No. This is an independent, third-party plugin with no affiliation\nwith Kadence WP.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>2.1.2<\/h4>\n\n<ul>\n<li>Renamed to \"JJCM Editor Theme Access for Kadence\" (slug:\njjcm-editor-theme-access-for-kadence), per WordPress.org plugin\nreview naming guidelines.<\/li>\n<\/ul>\n\n<h4>2.1.1<\/h4>\n\n<ul>\n<li>Renamed the main class to ETAK_Theme_Access to use a short, unique\nplugin prefix (WordPress.org coding standards).<\/li>\n<li>Removed the manual load_plugin_textdomain() call \u2014 translations for\nplugins hosted on WordPress.org are loaded automatically since\nWordPress 4.6.<\/li>\n<\/ul>\n\n<h4>2.1.0<\/h4>\n\n<ul>\n<li>The elevation now only applies when the active theme is actually\nKadence (or a child theme), checked via get_template(). The plugin\ncan stay active on any site, with no effect on themes other than\nKadence.<\/li>\n<\/ul>\n\n<h4>2.0.0<\/h4>\n\n<ul>\n<li>Architecture change: the elevation now includes manage_options (in\naddition to edit_theme_options and customize), since Kadence\nrequires manage_options to display its own Customizer panels. The\ngrant is strictly limited to nonce-verified Customizer\/Kadence\nrequests, and is never persisted to the database.<\/li>\n<\/ul>\n\n<h4>1.6.0<\/h4>\n\n<ul>\n<li>Renamed from \"Kadence Editor Theme Access\" to \"Editor Theme Access\nfor Kadence\".<\/li>\n<\/ul>\n\n<h4>1.5.0<\/h4>\n\n<ul>\n<li>Removed per-user ID filtering; edit_theme_options is granted to all\nEditors.<\/li>\n<\/ul>\n\n<h4>1.4.0<\/h4>\n\n<ul>\n<li>Added environment variable and text file as configuration sources\nfor the authorized editor list.<\/li>\n<\/ul>\n\n<h4>1.3.0<\/h4>\n\n<ul>\n<li>Authorized editor list defined outside the database.<\/li>\n<\/ul>\n\n<h4>1.2.0<\/h4>\n\n<ul>\n<li>(Reverted) Settings page under Users \u2192 Kadence Access.<\/li>\n<\/ul>\n\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>Simplified the edit_theme_options grant.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>First public release.<\/li>\n<\/ul>","raw_excerpt":"Gives the Editor role the same access to the Kadence Customizer that an Administrator has, without ever writing anything to the database.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/380851","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=380851"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/jjcm1962"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=380851"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=380851"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=380851"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=380851"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=380851"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=380851"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}