CVE-2025-12027: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-12027 is a Missing Authorization vulnerability in the Mesmerize Companion plugin for WordPress, affecting all versions up to and including 1.6.158. The flaw allows authenticated attackers with subscriber-level access or above to perform unauthorized data modifications on sites running the Mesmerize theme. It was published on February 19, 2026, and carries a CVSS v3.1 base score of 4.3 (Medium) (Red Hat CVE).

Technical details

The vulnerability is classified as CWE-862 (Missing Authorization) and stems from the absence of capability checks on the openPageInCustomizer and openPageInDefaultEditor functions within the plugin. Any authenticated user — including those with only subscriber-level privileges — can invoke these functions over the network without requiring elevated permissions or user interaction. This allows attackers to mark arbitrary pages as maintainable, wrap page content in custom sections, alter page template metadata, and toggle the default editor flag (Red Hat CVE).

Impact

Exploitation of this vulnerability results in unauthorized modification of WordPress site content and configuration, specifically affecting page integrity. An attacker with a basic subscriber account can manipulate page templates and editor settings across the site, potentially disrupting site appearance or functionality. There is no confidentiality or availability impact; the risk is limited to low-severity integrity compromise (Red Hat CVE).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2025-12027. The EPSS score is approximately 0.025%, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been identified (Red Hat CVE).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Mesmerize theme with the Mesmerize Companion plugin version 1.6.158 or earlier installed and active.
  2. Account Registration: Register or obtain a low-privilege account (subscriber level or above) on the target WordPress site.
  3. Craft Unauthorized Request: As an authenticated subscriber, send a crafted HTTP POST request directly invoking the openPageInCustomizer or openPageInDefaultEditor AJAX actions (e.g., via wp-admin/admin-ajax.php) targeting a specific page ID.
  4. Modify Page Data: The missing capability check allows the request to succeed, enabling the attacker to mark arbitrary pages as maintainable, inject custom section wrappers, alter template metadata, or toggle the default editor flag without administrator authorization (Red Hat CVE).

Indicators of compromise

  • Logs: WordPress access logs showing authenticated POST requests to wp-admin/admin-ajax.php with actions openPageInCustomizer or openPageInDefaultEditor originating from low-privilege user accounts.
  • Database: Unexpected changes to WordPress page metadata (e.g., _wp_page_template, custom section flags, or maintainable page markers) not initiated by administrators.
  • User Activity: Subscriber-level accounts performing page modification actions typically reserved for editors or administrators in WordPress audit logs.

Mitigation and workarounds

Users should update the Mesmerize Companion plugin to a version beyond 1.6.158 that includes proper capability checks on the affected functions. Until a patched version is available or applied, site administrators should consider restricting user registration to prevent untrusted subscriber accounts, or temporarily deactivating the plugin if it is not essential. Monitoring WordPress user activity logs for unauthorized page modification attempts is also recommended (Red Hat CVE).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management