PT-2026-3002 · WordPress+1 · Kalium+1

CVE-2025-12895

·

Publicado

2026-01-15

·

Atualizado

2026-01-15

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Kalium 3 | Creative WordPress & WooCommerce Theme versions prior to 3.30
Description The Kalium theme for WordPress is susceptible to unauthorized email sending. This is due to a missing capability check within the kalium vc contact form request() function. This flaw allows unauthenticated attackers to utilize the theme as an open mail relay, enabling them to send emails to arbitrary email addresses through the server.
Recommendations Update to version 3.30 or later.

Correção

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-12895

Produtos afetados

Kalium
Woocommerce