VYPR
Medium severity5.3NVD Advisory· Published Sep 9, 2025· Updated Apr 29, 2026

CVE-2025-53348

CVE-2025-53348

Description

Missing Authorization vulnerability in Laborator Kalium kalium allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kalium: from n/a through <= 3.18.3.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Kalium theme ≤3.18.3 has a missing authorization vulnerability allowing unprivileged attackers to exploit incorrectly configured access controls.

Vulnerability

Overview

CVE-2025-53348 is a missing authorization vulnerability in the Laborator Kalium WordPress theme, affecting versions from n/a through 3.18.3. The issue stems from incorrectly configured access control security levels, which means certain functions lack proper authorization checks, nonce tokens, or authentication requirements [1].

Exploitation

An unauthenticated or low-privileged attacker can exploit this broken access control to perform actions that should require higher privileges. The vulnerability is particularly dangerous because it can be used in mass-exploit campaigns targeting thousands of websites simultaneously, regardless of site traffic or popularity [1].

Impact

Successful exploitation allows an attacker to bypass intended access restrictions, potentially leading to unauthorized data access, modification, or other privileged operations within the affected WordPress installation. The CVSS v3 base score of 5.3 (Medium) reflects the moderate severity, though the ease of mass exploitation increases the real-world risk [1].

Mitigation

The vendor has not released a patch for versions beyond 3.18.3, and users are advised to update the theme immediately. If updating is not possible, contacting a hosting provider or web developer for assistance is recommended [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.