theme

Vikinger Vulnerabilities

4 known security issues reported for the Vikinger WordPress theme. Most recent disclosed Jul 1, 2025.

2 high

Running Vikinger on your site? Check whether your installed version is affected.

Scan your site free

Vikinger <= 1.9.32 - Authenticated (Subscriber+) Arbitrary File Deletion via vikinger_delete_activity_media_ajax Function

high

The Vikinger theme for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the vikinger_delete_activity_media_ajax() function in all versions up to, and including, 1.9.32. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arb...

CVSS:
8.1
Affected:
up to 1.9.32
Fixed in:
1.9.33
Disclosed:
Jul 1, 2025

CVE-2025-4946 on NVD →

Vikinger <= 1.9.30 - Authenticated (Subscriber+) Privilege Escalation via 'vikinger_user_meta_update_ajax'

high

The Vikinger theme for WordPress is vulnerable to privilege in all versions up to, and including, 1.9.30. This is due to insufficient user_meta restrictions in the 'vikinger_user_meta_update_ajax' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to escalate their pri...

CVSS:
8.8
Affected:
up to 1.9.30
Fixed in:
1.9.31
Disclosed:
Apr 24, 2025

CVE-2025-2238 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database