HIGH
Zegen - Church WordPress Theme <= 1.1.9 - Missing Authorization to Authenticated (Subscriber+) Theme Options Updates
Published Mar 14, 2025
8.8
HIGHCVSS 3.1
EPSS 0.28%
Description
The Zegen - Church WordPress Theme theme for WordPress is vulnerable to unauthorized access due to a missing capability check on several AJAX endpoints in all versions up to, and including, 1.1.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to import, export, and update theme options.
Affected products
-
- Version 0StatusaffectedConstraints<=1.1.9
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Zozothemes | Zegen - Church WordPress Theme | unaffected |
|
- ≤ 1.1.9
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-7557 Advisory
- https://themeforest.net/item/zegen-church-wordpress-theme/25116823 Product
- https://www.wordfence.com/threat-intel/vulnerabilities/id/a04db024-5198-490f-bf5f-d5bad1b21ce4?source=cve Third Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-7557 | Advisory | |
| https://themeforest.net/item/zegen-church-wordpress-theme/25116823 | Product | |
| https://www.wordfence.com/threat-intel/vulnerabilities/id/a04db024-5198-490f-bf5f-d5bad1b21ce4?source=cve | Third Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Wordfence
Published Mar 14, 2025
Updated Apr 8, 2026
Reserved Mar 13, 2025
Link CVE-2025-2289
CISA Vulnrichment
Updated Mar 14, 2025
ENISA EUVD
EUVD-2025-7557 Assigner Wordfence
Published Mar 14, 2025
Updated Apr 8, 2026
Exploited since n/a
Link EUVD-2025-7557