Impact
Laborator Kalium theme versions 3.25 and earlier contain an Improper Control of Generation of Code flaw, allowing an attacker to inject and execute arbitrary code. The vulnerability is rooted in CWE‑94 and permits exploitation of the theme’s code generation mechanisms. Successful exploitation would break the confidentiality, integrity, and availability of the affected WordPress site, granting full control to an attacker.
Affected Systems
The Kalium theme bundled with WordPress, from version N/A through 3.25, is affected. No additional vendor or product variants are listed. Any WordPress instance using the Kalium theme 3.25 or older is vulnerable.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity while the EPSS of less than 1% shows a low probability of exploitation in the wild. It is not listed in the CISA KEV catalog. The likely attack vector is through the web interface of the vulnerable theme, although the exact entry point is not detailed in the provided data. An attacker could craft malicious requests that trigger the code generation logic, resulting in arbitrary code execution on the server.
OpenCVE Enrichment