PT-2025-30969 · WordPress · Kallyas Theme

Matthew Rollings

·

Published

2025-07-26

·

Updated

2025-07-26

·

CVE-2025-6991

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions kallyas theme for WordPress versions prior to 4.21.1
Description The kallyas theme for WordPress is susceptible to Local File Inclusion via the TH LatestPosts4 widget. Authenticated attackers with Contributor-level access or higher can include and execute arbitrary .php files on the server. This can lead to bypassing access controls, obtaining sensitive data, or achieving code execution if .php file uploads are permitted.
Recommendations Update to kallyas theme for WordPress version 4.21.1 or later.

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-6991

Affected Products

Kallyas Theme