PT-2025-33905 · Themegrill+1 · Themegrill-Demo-Importer+1
Dmitry Ignatyev
·
Published
2025-08-20
·
Updated
2025-08-20
·
CVE-2025-9202
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
ColorMag versions prior to 4.0.20
Description:
The ColorMag theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check in the
welcome notice import handler() function. This allows authenticated attackers with Subscriber-level access or higher to install the ThemeGrill Demo Importer plugin.Recommendations:
Update ColorMag to version 4.0.20 or later.
As a temporary workaround, restrict access for users with Subscriber-level access or lower.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Colormag
Themegrill-Demo-Importer