CVE-2025-49926

7.3

Laborator · Kalium

The Kalium WordPress theme contains a code injection vulnerability that allows unauthenticated remote attackers to execute arbitrary code.

Executive summary

The Laborator Kalium theme for WordPress is vulnerable to unauthenticated code injection, posing a significant risk of remote compromise.

Vulnerability

This vulnerability is classified as improper control of generation of code, or code injection (CWE-94). The flaw allows an unauthenticated, remote attacker to inject and execute arbitrary code within the context of the affected WordPress environment.

Business impact

Successful exploitation of this vulnerability can lead to unauthorized code execution, potentially allowing an attacker to gain full control over the affected website. Given the CVSS score of 7.3, this represents a high-severity risk that could lead to data theft, site defacement, or the deployment of persistent backdoors, significantly impacting business operations and user trust.

Remediation

Immediate Action: Since no specific patch version is currently identified, users should disable the Kalium theme or switch to an alternative until an official security update is released by Laborator.

Proactive Monitoring: Security teams should review web server access logs for suspicious HTTP requests, particularly those containing encoded payloads or unexpected script execution patterns.

Compensating Controls: Deploy or update Web Application Firewall (WAF) rules to inspect incoming traffic for common code injection vectors targeting the WordPress environment.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the high severity and the potential for unauthenticated remote code execution, this vulnerability requires immediate attention. Administrators must monitor vendor communications for a security patch and apply it as soon as it becomes available to prevent potential system compromise.

Sources

Originally found and disclosed by Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) | Patchstack Bug Bounty Program, per the CVE Program record.