PT-2025-51051 · WordPress · Mavix Education Theme

Published

2025-12-13

·

Updated

2025-12-13

·

CVE-2025-11164

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Mavix Education theme for WordPress versions 1.0 and earlier
Description The Mavix Education theme for WordPress has an issue where data can be modified without authorization. This is due to a missing capability check on the mavix education activate plugin AJAX action. Attackers with Subscriber-level access or higher can activate the Creativ Demo Importer plugin. The vulnerable component is the mavix education activate plugin AJAX action.
Recommendations Update to a version of the Mavix Education theme for WordPress that addresses this issue.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-11164

Affected Products

Mavix Education Theme