Capella | Restaurant WordPress <= 2.5.5 - Unauthenticated SQL Injection
high
The Capella | Restaurant WordPress theme for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.5.5. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to app...
- CVSS:
- 7.5
- Affected:
- up to 2.5.5
- Fix:
- No patched version reported
- Disclosed:
- Aug 20, 2026
CVE-2025-15688 on NVD →
Capella | Restaurant WordPress <= 2.5.5 - Unauthenticated Privilege Escalation
high
The Capella | Restaurant WordPress theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.5.5. This is due to insufficient restriction on the capabilities a user may grant themselves. This makes it possible for unauthenticated attackers to elevate their privileges beyond those...
- CVSS:
- 7.3
- Affected:
- up to 2.5.5
- Fix:
- No patched version reported
- Disclosed:
- Aug 20, 2026
CVE-2025-15689 on NVD →
Capella [capella] <= 2.5.5 (unfixed)
unknown
[en] Deserialization of Untrusted Data vulnerability in ThemeGoods Capella capella allows Object Injection.This issue affects Capella: from n/a through <= 2.5.5.
- Affected:
- up to 2.5.5
- Fix:
- No patched version reported
- Disclosed:
- Feb 20, 2026
CVE-2025-69370 on NVD →
Capella <= 2.5.5 - Unauthenticated PHP Object Injection
high
The Capella theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.5.5 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an ad...
- CVSS:
- 8.1
- Affected:
- up to 2.5.5
- Fixed in:
- 2.5.6
- Disclosed:
- Jan 29, 2026
CVE-2025-69370 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database