PT-2026-3002 · WordPress+1 · Kalium+1

Published

2026-01-15

·

Updated

2026-01-15

·

CVE-2025-12895

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Kalium 3 | Creative WordPress & WooCommerce Theme versions prior to 3.30
Description The Kalium theme for WordPress is susceptible to unauthorized email sending. This is due to a missing capability check within the kalium vc contact form request() function. This flaw allows unauthenticated attackers to utilize the theme as an open mail relay, enabling them to send emails to arbitrary email addresses through the server.
Recommendations Update to version 3.30 or later.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-12895

Affected Products

Kalium
Woocommerce