CVE-2019-25142: Extendthemes Materialis
High severity, CVSS 8.8. EPSS: 1.3% chance of exploitation in the next 30 days.
The Mesmerize & Materialis themes for WordPress are vulnerable to authenticated options change in versions up to, and including,1.6.89 (Mesmerize) and 1.0.172 (Materialis). This is due to 'companion_disable_popup' function only checking the nonce while sending user input to the 'update_option' function. This makes it possible for authenticated attackers to change otherwise restricted options.
Affected products
- Extendthemes Materialis: before 1.0.173 (fixed in 1.0.173)
- Extendthemes Mesmerize: before 1.6.90 (fixed in 1.6.90)
Published 2023-06-07. Last modified 2026-06-17.