WordPress Spacious Theme Missing Authorization Vulnerability in Demo Data Import
Vulnerability
A vulnerability exists in the Spacious theme for WordPress, in all versions through 1.9.11, allowing unauthorized data modification. The issue arises from a lack of capability checks in the 'welcome_notice_import_handler' function. This flaw enables authenticated attackers with Subscriber-level access or higher to import demo data into their sites.
Impact
Exploitation of this vulnerability allows for unauthorized importation of demo data by authenticated users with Subscriber-level access or above.
Remediation
Users can update to version 1.9.12 or a newer patched version to address this vulnerability.
Added: Aug 22, 2025, 12:29 PM
Updated: Aug 22, 2025, 12:29 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
0.6exploitability
5.9remediation
7.7relevance
0.4threat
3.2urgency
2.9incentive
1.7Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
