CVE-2025-49926
WordPress Kalium theme <= 3.25 - Arbitrary Code Execution vulnerability
CVSS Score
7.3
EPSS Score
0.0%
EPSS Percentile
0th
Improper Control of Generation of Code ('Code Injection') vulnerability in Laborator Kalium kalium allows Code Injection.This issue affects Kalium: from n/a through <= 3.25.
| CWE | CWE-94 |
| Vendor | laborator |
| Product | kalium |
| Published | Oct 22, 2025 |
| Last Updated | Apr 1, 2026 |
Stay Ahead of the Next One
Get instant alerts for laborator kalium
Be the first to know when new high vulnerabilities affecting laborator kalium are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Laborator / Kalium
0 โค 3.25
References
Credits
Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) | Patchstack Bug Bounty Program