CVE-2025-9202: ColorMag <= 4.0.19 - Missing Authorization to Authenticated (Subscriber+) ThemeGrill Demo Importer Plugin Installation
The ColorMag theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the welcomenoticeimporthandler() function in all versions up to, and including, 4.0.19. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install the ThemeGrill Demo Importer plugin.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9202?
CVE-2025-9202 has a medium severity level due to its potential for unauthorized data modification.
How do I fix CVE-2025-9202?
To fix CVE-2025-9202, update the ColorMag theme to version 4.0.20 or higher, which includes the necessary capability checks.
Who is affected by CVE-2025-9202?
Users of the ColorMag theme for WordPress versions up to and including 4.0.19 are affected by CVE-2025-9202.
Can authenticated attackers exploit CVE-2025-9202?
Yes, authenticated attackers with Subscriber-level access can exploit CVE-2025-9202 to modify data.
What is the impact of CVE-2025-9202 on WordPress sites?
The impact of CVE-2025-9202 includes unauthorized modification of data on WordPress sites using the vulnerable theme.