Description
Missing Authorization vulnerability in Climax Themes Kata Plus kata-plus allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kata Plus: from n/a through <= 1.5.3.
Published: 2025-06-20
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A missing authorization flaw in the Climax Themes Kata Plus WordPress plugin permits an attacker to exploit incorrectly configured access control security levels. The vulnerability allows unauthorized users to perform actions that should be restricted, potentially enabling the creation, modification, or deletion of posts, settings, or other protected resources. The weakness is catalogued as CWE‑862, a classic broken access control issue, and could lead to unauthorized content manipulation, privacy breach, or exposure of sensitive data if not stopped.

Affected Systems

Climax Themes Kata Plus plugin, versions up to and including 1.5.3, is affected. Any website running Kata Plus in this version range is vulnerable.

Risk and Exploitability

The CVSS score of 5.4 indicates moderate severity, and the EPSS score of less than 1% shows a very low likelihood of exploitation currently. The vulnerability is not listed in the CISA KEV catalog. Attackers would likely deliver the exploit via HTTP requests to plugin‑specific URLs that lack proper permission checks; the attack can be launched from a remote web client once the target site hosts the vulnerable plugin. No additional requirements are specified.

Generated by OpenCVE AI on April 30, 2026 at 10:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Kata Plus plugin to a version newer than 1.5.3, removing the affected code from the installation.
  • If an upgrade is not possible immediately, restrict access to the plugin’s administrative pages via server‑level rules (e.g., .htaccess or equivalent) or by limiting user roles that have permission to invoke the plugin’s features.
  • Remove or disable the Kata Plus plugin entirely if it is not needed for site functionality or replace it with a reputable alternative.

Generated by OpenCVE AI on April 30, 2026 at 10:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-28347 Missing Authorization vulnerability in Climax Themes Kata Plus allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Kata Plus: from n/a through 1.5.3.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Climax Themes Kata Plus allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Kata Plus: from n/a through 1.5.3. Missing Authorization vulnerability in Climax Themes Kata Plus kata-plus allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kata Plus: from n/a through <= 1.5.3.
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}


Mon, 23 Jun 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 20 Jun 2025 15:15:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Climax Themes Kata Plus allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Kata Plus: from n/a through 1.5.3.
Title WordPress Kata Plus plugin <= 1.5.3 - Broken Access Control Vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:15.914Z

Reserved: 2025-06-11T16:08:11.573Z

Link: CVE-2025-50009

cve-icon Vulnrichment

Updated: 2025-06-23T16:10:38.632Z

cve-icon NVD

Status : Deferred

Published: 2025-06-20T15:15:26.360

Modified: 2026-04-23T15:31:58.337

Link: CVE-2025-50009

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T11:00:15Z

Weaknesses