Kalium WordPress Theme Unauthenticated Email Relay Vulnerability

Vulnerability

A vulnerability in the Kalium WordPress theme, specifically in versions through 3.29, allows for unauthorized email sending. This issue arises from a missing capability check in the 'kalium_vc_contact_form_request()' function. As a result, unauthenticated attackers can exploit the theme as an open mail relay, sending emails to arbitrary addresses on behalf of the server.

Impact

Exploitation of this vulnerability could lead to unauthorized email being sent from the server, potentially allowing for phishing attacks or the distribution of spam.

Remediation

Users can update to Kalium version 3.30 or later, where this vulnerability has been patched.

Added: Jan 15, 2026, 2:28 PM
Updated: Jan 15, 2026, 2:28 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
7.4
remediation
0.0
relevance
2.1
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.