Missing Authorization Vulnerability in Hogash Kallyas Theme
CVE-2025-62017

5.4MEDIUM

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
6 November 2025

What is CVE-2025-62017?

The Hogash Kallyas Theme is affected by a missing authorization vulnerability that allows unauthorized users to access restricted functionalities. This security flaw can enable potential attackers to manipulate data and compromise site integrity, particularly in versions up to 4.22.0. The vulnerability underscores the importance of implementing proper access controls to safeguard against unauthorized access and maintain robust security practices.

Affected Version(s)

Kallyas <= n/a

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rafie Muhammad (Patchstack)
.