Description
Missing Authorization vulnerability in hogash KALLYAS kallyas.This issue affects KALLYAS: from n/a through <= 4.22.0.
Published: 2025-11-06
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing authorization flaw in the KALLYAS WordPress theme which can allow an attacker to bypass intended access controls and perform privileged actions without proper authentication. This weakness is defined by CWE‑862 and could enable users with insufficient privileges to gain in‑depth access to restricted sections or functionalities of a website that uses the affected theme.

Affected Systems

The problem is present in all versions of the KALLYAS theme up to and including 4.22.0. Any WordPress site that has installed or is continuing to run KALLYAS <= 4.22.0 is impacted. The flaw may affect sites that rely on the theme for layout and content management, potentially exposing administrative pages or backend scripts.

Risk and Exploitability

The CVSS base score of 5.4 indicates a moderate level of risk. The EPSS score is below 1%, showing that the likelihood of exploitation is low at present, and the vulnerability is not currently listed in the CISA KEV catalog. Based on the description, the likely attack vector would involve an attacker having some access to the site’s content‑management system or discovering URLs controlled by the theme’s internal access controls. Until a patch is applied, the risk can be moderated by the limited exploitation probability, but the potential impact of a successful attack remains significant because of the compromised integrity and confidentiality of the site’s protected resources.

Generated by OpenCVE AI on April 30, 2026 at 05:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the KALLYAS theme to version 4.23 or later.
  • If upgrading is not immediately possible, restrict direct access to theme files that enable privileged functionality using server‑level controls such as .htaccess rules or web‑application firewall rules.
  • Apply additional layer‑of‑defense checks in the application code to enforce role‑based access controls for any administrative or sensitive endpoints that the theme exposes.

Generated by OpenCVE AI on April 30, 2026 at 05:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}

cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in hogash Kallyas kallyas.This issue affects Kallyas: from n/a through <= 4.22.0. Missing Authorization vulnerability in hogash KALLYAS kallyas.This issue affects KALLYAS: from n/a through <= 4.22.0.

Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Thu, 13 Nov 2025 11:30:00 +0000


Thu, 13 Nov 2025 10:45:00 +0000


Thu, 06 Nov 2025 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Hogash
Hogash kallyas
Wordpress
Wordpress wordpress
Vendors & Products Hogash
Hogash kallyas
Wordpress
Wordpress wordpress

Thu, 06 Nov 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 06 Nov 2025 16:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in hogash Kallyas kallyas.This issue affects Kallyas: from n/a through <= 4.22.0.
Title WordPress Kallyas theme <= 4.22.0 - Broken Access Control vulnerability
Weaknesses CWE-862
References

Subscriptions

Hogash Kallyas
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:59.087Z

Reserved: 2025-10-07T15:34:13.976Z

Link: CVE-2025-62017

cve-icon Vulnrichment

Updated: 2025-11-06T17:59:28.638Z

cve-icon NVD

Status : Deferred

Published: 2025-11-06T16:16:08.567

Modified: 2026-04-27T17:16:29.847

Link: CVE-2025-62017

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T05:15:28Z

Weaknesses