PT-2025-34340 · WordPress · Spacious

Dmitry Ignatyev

·

Published

2025-08-22

·

Updated

2025-08-22

·

CVE-2025-9331

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Spacious theme for WordPress versions prior to 1.9.12
Description: The Spacious theme for WordPress is susceptible to unauthorized data modification due to the absence of a capability check within the welcome notice import handler function. Authenticated attackers possessing Subscriber-level access or higher can import demo data into the site.
Recommendations: Update the Spacious theme to version 1.9.12 or later.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-9331

Affected Products

Spacious