CVE-2025-49926: WordPress Kalium theme <= 3.25 - Arbitrary Code Execution vulnerability
Published Oct 22, 2025
·Updated
Improper Control of Generation of Code ('Code Injection') vulnerability in Laborator Kalium kalium allows Code Injection.This issue affects Kalium: from n/a through <= 3.25.
Affected Software
2 affected components
Laborator Kalium<=3.25
WordPress Kalium theme<=3.25
Event History
Oct 22, 2025
CVE Published
via MITRE·02:32 PM
Data Sourced
via MITRE·02:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-49926?
CVE-2025-49926 is categorized as a high severity vulnerability due to its potential to allow arbitrary code execution.
2
What versions are affected by CVE-2025-49926?
CVE-2025-49926 affects Laborator Kalium versions up to and including 3.25.
3
How do I fix CVE-2025-49926?
To mitigate CVE-2025-49926, update Laborator Kalium to a version that is not affected, above 3.25.
4
What type of vulnerability is CVE-2025-49926?
CVE-2025-49926 is an improper control of generation of code, specifically a code injection vulnerability.
5
Who is impacted by CVE-2025-49926?
Users of Laborator Kalium and the WordPress Kalium theme, specifically those on versions up to 3.25, are impacted by CVE-2025-49926.