Unauthorized Data Modification in ColorMag Theme for WordPress
CVE-2025-9202
4.3MEDIUM
What is CVE-2025-9202?
The ColorMag theme for WordPress contains a vulnerability that allows authenticated attackers with Subscriber-level access or higher to exploit a missing capability check in the welcome_notice_import_handler() function. This flaw can lead to unauthorized data modification, enabling the installation of the ThemeGrill Demo Importer plugin. This issue affects all versions of the ColorMag theme up to and including version 4.0.19, underscoring the importance of securing WordPress themes against unauthorized modifications.
Affected Version(s)
ColorMag * <= 4.0.19