CVE-2025-53349: WordPress Kalium Theme <= 3.18.3 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Laborator Kalium kalium allows Reflected XSS.This issue affects Kalium: from n/a through <= 3.18.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-53349?
CVE-2025-53349 is classified as a high-severity vulnerability due to its potential for reflected Cross-site Scripting (XSS) attacks.
How do I fix CVE-2025-53349?
To remediate CVE-2025-53349, you should update the Laborator Kalium theme to version 3.18.4 or later.
What software is affected by CVE-2025-53349?
CVE-2025-53349 affects Laborator Kalium and WordPress Kalium theme versions up to and including 3.18.3.
What is reflected Cross-site Scripting in context of CVE-2025-53349?
Reflected Cross-site Scripting in CVE-2025-53349 allows attackers to inject malicious scripts into web pages that are then executed in the user's browser.
When was CVE-2025-53349 disclosed?
CVE-2025-53349 was publicly disclosed as a vulnerability affecting the Kalium theme.