Description
The Mesmerize Companion plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the "openPageInCustomizer" and "openPageInDefaultEditor" functions in all versions up to, and including, 1.6.158. This makes it possible for authenticated attackers - with subscriber level access and above, on websites with the Mesmerize theme activated - to mark arbitrary pages as maintainable, wrap their content in custom sections, change page template metadata, and toggle the default editor flag without proper authorization.
Problem types
Product status
* (semver)
Timeline
| 2025-10-13: | Discovered |
| 2026-01-28: | Vendor Notified |
| 2026-02-18: | Disclosed |
Credits
Rafshanzani Suhada
References
www.wordfence.com/...-b8ca-43cc-92d7-eb3830381512?source=cve
plugins.trac.wordpress.org/...ompanion&sfp_email=&sfph_mail=
plugins.trac.wordpress.org/...ompanion&sfp_email=&sfph_mail=