Description
Cross-Site Request Forgery (CSRF) vulnerability in Laborator Kalium kalium allows Cross Site Request Forgery.This issue affects Kalium: from n/a through <= 3.18.3.
Published: 2025-08-14
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A CSRF flaw in the Laborator Kalium WordPress theme allows an attacker to trick an authenticated site user into performing state‑changing operations without the user’s consent. The vulnerability can be used to execute any action that requires a logged‑in user, potentially leading to unauthorized content changes or site configuration changes. Based on the supplied CVSS score of 4.3, the impact is moderate, reflecting the risk of unintended actions rather than immediate code execution.

Affected Systems

WordPress sites that use the Laborator Kalium theme version 3.18.3 or earlier are affected. The issue cuts across all versions of the theme from its earliest release up to the specified 3.18.3 release. Any site that has not upgraded beyond this version remains vulnerable.

Risk and Exploitability

The EPSS score of less than 1% indicates a very low probability of exploitation in the wild, and the vulnerability is currently not listed in CISA’s KEV catalog. The most likely attack vector involves an attacker crafting a link or form that forces the victim’s browser to send a forged request to the site while the victim is authenticated. Because the flaw exploits the lack of anti‑CSRF tokens on certain theme actions, successful exploitation requires the user to be logged in and to interact with the malicious payload, which limits the window of opportunity. However, anyone possessing such a payload could potentially cause unintended changes to the site’s content or settings.

Generated by OpenCVE AI on April 30, 2026 at 08:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Kalium theme to a version newer than 3.18.3, which removes the CSRF vulnerability.
  • If an upgrade is not immediately possible, disable or restrict the theme functionality that is susceptible to CSRF, such as by removing or protecting the related admin pages.
  • Implement or verify that your WordPress installation includes proper CSRF protection on all state‑changing endpoints, ensuring that each request carries a valid anti‑CSRF token.

Generated by OpenCVE AI on April 30, 2026 at 08:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-24900 Cross-Site Request Forgery (CSRF) vulnerability in Laborator Kalium allows Cross Site Request Forgery. This issue affects Kalium: from n/a through 3.18.3.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Laborator Kalium allows Cross Site Request Forgery. This issue affects Kalium: from n/a through 3.18.3. Cross-Site Request Forgery (CSRF) vulnerability in Laborator Kalium kalium allows Cross Site Request Forgery.This issue affects Kalium: from n/a through <= 3.18.3.
Title WordPress Kalium Theme plugin <= 3.18.3 - Cross Site Request Forgery (CSRF) Vulnerability WordPress Kalium Theme <= 3.18.3 - Cross Site Request Forgery (CSRF) Vulnerability
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Fri, 15 Aug 2025 08:15:00 +0000

Type Values Removed Values Added
First Time appeared Laborator
Laborator kalium
Wordpress
Wordpress wordpress
Vendors & Products Laborator
Laborator kalium
Wordpress
Wordpress wordpress

Thu, 14 Aug 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 14 Aug 2025 18:30:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Laborator Kalium allows Cross Site Request Forgery. This issue affects Kalium: from n/a through 3.18.3.
Title WordPress Kalium Theme plugin <= 3.18.3 - Cross Site Request Forgery (CSRF) Vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

Laborator Kalium
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:24.211Z

Reserved: 2025-06-27T11:59:38.158Z

Link: CVE-2025-53347

cve-icon Vulnrichment

Updated: 2025-08-14T20:03:16.414Z

cve-icon NVD

Status : Deferred

Published: 2025-08-14T19:15:36.157

Modified: 2026-04-23T15:32:32.033

Link: CVE-2025-53347

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T09:00:20Z

Weaknesses