PT-2025-33905 · Themegrill+1 · Themegrill-Demo-Importer+1

Dmitry Ignatyev

·

Published

2025-08-20

·

Updated

2025-08-20

·

CVE-2025-9202

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions: ColorMag versions prior to 4.0.20
Description: The ColorMag theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check in the welcome notice import handler() function. This allows authenticated attackers with Subscriber-level access or higher to install the ThemeGrill Demo Importer plugin.
Recommendations: Update ColorMag to version 4.0.20 or later. As a temporary workaround, restrict access for users with Subscriber-level access or lower.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-9202

Affected Products

Colormag
Themegrill-Demo-Importer