PT-2025-44721 · WordPress · Kallyas

Matthew Rollings

·

Published

2025-11-01

·

Updated

2025-11-01

·

CVE-2025-6990

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions kallyas versions prior to 4.24.0
Description The kallyas theme for WordPress is susceptible to Remote Code Execution through the TH PhpCode pagebuilder widget. The issue arises because the theme does not restrict access to the code editor widget for users who are not administrators. This allows authenticated attackers with Contributor-level access or higher to execute code on the server. The TH PhpCode widget is the specific component involved in this issue.
Recommendations Update kallyas to version 4.24.0 or later.

Fix

RCE

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-6990

Affected Products

Kallyas