WordPress Spacious Theme Missing Authorization Vulnerability in Demo Data Import

Vulnerability

A vulnerability exists in the Spacious theme for WordPress, in all versions through 1.9.11, allowing unauthorized data modification. The issue arises from a lack of capability checks in the 'welcome_notice_import_handler' function. This flaw enables authenticated attackers with Subscriber-level access or higher to import demo data into their sites.

Impact

Exploitation of this vulnerability allows for unauthorized importation of demo data by authenticated users with Subscriber-level access or above.

Remediation

Users can update to version 1.9.12 or a newer patched version to address this vulnerability.

Added: Aug 22, 2025, 12:29 PM
Updated: Aug 22, 2025, 12:29 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
5.9
remediation
7.7
relevance
0.4
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.