High 8.8 Unfixed
2025-11-01≤ 4.24.0
Kallyas <= 4.24.0 - Authenticated (Contributor+) Remote Code Execution
Minimum safe version
4.24.0
Update to 4.24.0 or later to address 6 fixable vulnerabilities
Kallyas <= 4.24.0 - Authenticated (Contributor+) Remote Code Execution
Kallyas <= 4.23.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
CVE-2025-63060
CVE-2025-63061
CVE-2025-62018
CVE-2025-62017
CVE-2025-62016
Kallyas <= 4.21.0 - Authenticated (Contributor+) Arbitrary Folder Deletion
WordPress KALLYAS - Creative eCommerce Multi-Purpose WordPress Theme Theme <= 4.21.0 is vulnerable to Local File Inclusion