VYPR

Altair

by WordPress

Source repositories

CVEs (3)

  • CVE-2025-32928CriMay 19, 2025
    risk 0.64cvss 9.8epss 0.00

    Deserialization of Untrusted Data vulnerability in ThemeGoods Altair altair allows Object Injection.This issue affects Altair: from n/a through <= 5.2.2.

  • CVE-2024-12922CriMar 19, 2025
    risk 0.64cvss 9.8epss 0.01

    The Altair theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check within functions.php in all versions up to, and including, 5.2.4. This makes it possible for unauthenticated attackers to…

  • CVE-2025-53999MedAug 20, 2026
    risk 0.42cvss 6.5epss 0.00

    Unauthenticated Broken Access Control in Altair <= 5.2.2 versions.