Altair <= 5.2.2 - Missing Authorization
medium
The Altair theme for WordPress is vulnerable to unauthorized access in all versions up to, and including, 5.2.2. This is due to a missing capability check on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 5.2.2
- Fix:
- No patched version reported
- Disclosed:
- Aug 19, 2026
CVE-2025-53999 on NVD →
Altair <= 5.2.2 - Unauthenticated PHP Object Injection
critical
The Altair theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 5.2.2 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an add...
- CVSS:
- 9.8
- Affected:
- up to 5.2.2
- Fix:
- No patched version reported
- Disclosed:
- Apr 21, 2025
CVE-2025-32928 on NVD →
Altair <= 5.2.4 - Unauthenticated Arbitrary Options Update via pp_import_current
critical
The Altair theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check within functions.php in all versions up to, and including, 5.2.4. This makes it possible for unauthenticated attackers to update arbitrary options on the WordPress si...
- CVSS:
- 9.8
- Affected:
- up to 5.2.4
- Fixed in:
- 5.2.5
- Disclosed:
- Mar 18, 2025
CVE-2024-12922 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database