Kalium WordPress Theme Unauthenticated Email Relay Vulnerability
Vulnerability
A vulnerability in the Kalium WordPress theme, specifically in versions through 3.29, allows for unauthorized email sending. This issue arises from a missing capability check in the 'kalium_vc_contact_form_request()' function. As a result, unauthenticated attackers can exploit the theme as an open mail relay, sending emails to arbitrary addresses on behalf of the server.
Impact
Exploitation of this vulnerability could lead to unauthorized email being sent from the server, potentially allowing for phishing attacks or the distribution of spam.
Remediation
Users can update to Kalium version 3.30 or later, where this vulnerability has been patched.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
