VYPR
Medium severity5.4NVD Advisory· Published Feb 3, 2026· Updated Apr 15, 2026

CVE-2026-25021

CVE-2026-25021

Description

Missing Authorization vulnerability in Mizan Themes Mizan Demo Importer mizan-demo-importer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Mizan Demo Importer: from n/a through <= 0.1.3.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Missing authorization in Mizan Demo Importer plugin <=0.1.3 allows unauthenticated access to import functions, enabling potential site takeover.

Vulnerability

Overview The Mizan Demo Importer plugin for WordPress contains a missing authorization vulnerability (CWE-862) in versions up to 0.1.3. The plugin fails to properly verify access rights before allowing users to execute demo import functions, effectively providing unauthenticated access to functionality that should require higher privileges. [1]

Exploitation

An attacker does not need any authentication or prior privileges. By sending crafted HTTP requests to the vulnerable endpoint, they can trigger the import of arbitrary demo content. This can include malicious payloads or overwrite existing site settings. The flaw is classified as "Broken Access Control," indicating a lack of necessary permission checks. [1]

Impact

Successful exploitation allows an attacker to inject arbitrary content, potentially leading to site defacement, insertion of backdoors, or complete site takeover. The vulnerability is known to be exploited in mass campaigns targeting thousands of websites. [1]

Mitigation

The vendor has released version 0.1.4, which addresses the missing authorization. Users are strongly advised to update immediately. No workaround is available. Patchstack users can enable auto-updates for vulnerable plugins. [1]

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.