Vikinger <= 1.9.32 - Authenticated (Subscriber+) Arbitrary File Deletion via vikinger_delete_activity_media_ajax Function
high
The Vikinger theme for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the vikinger_delete_activity_media_ajax() function in all versions up to, and including, 1.9.32. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arb...
- CVSS:
- 8.1
- Affected:
- up to 1.9.32
- Fixed in:
- 1.9.33
- Disclosed:
- Jul 1, 2025
CVE-2025-4946 on NVD →
Vikinger <= 1.9.30 - Authenticated (Subscriber+) Privilege Escalation via 'vikinger_user_meta_update_ajax'
high
The Vikinger theme for WordPress is vulnerable to privilege in all versions up to, and including, 1.9.30. This is due to insufficient user_meta restrictions in the 'vikinger_user_meta_update_ajax' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to escalate their pri...
- CVSS:
- 8.8
- Affected:
- up to 1.9.30
- Fixed in:
- 1.9.31
- Disclosed:
- Apr 24, 2025
CVE-2025-2238 on NVD →
Vikinger [vikinger] < 1.9.31
unknown
- Affected:
- up to 1.9.31
- Fixed in:
- 1.9.31
CVE-2025-2238 on NVD →
Vikinger [vikinger] < 1.9.33
unknown
- Affected:
- up to 1.9.33
- Fixed in:
- 1.9.33
CVE-2025-4946 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database