CVE-2025-8595 Information

Description

The Zakra theme for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the welcome_notice_import_handler() function in all versions up to and including 4.1.5. This makes it possible for authenticated attackers with Subscriber-level access and above to import demo settings.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Reference

https://research.cleantalk.org/cve-2025-8595/ https://themes.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=281307%40zakra%2F4.1.6&old=276128%40zakra%2F4.1.5 https://www.wordfence.com/threat-intel/vulnerabilities/id/4da012dc-7e58-479a-813e-762eb28297bf?source=cve

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

LOW

Base Score

NONE

Base Severity

4.3

CNNVD-202508-490 (Published: 2025-08-06)

Share on: