WordPress security by component
Kalles Addons
Kalles Addons (kalles-addons) is a WordPress plugin with 3 published CVE records in this archive. The latest tracked vulnerability was published Aug 31, 2026; the highest published CVSS base score is 9.8.
Plugin slug:
kalles-addonsLatest vulnerability
CVE-2026-81778: Kalles Addons permits Subscriber-level XSS
Kalles Addons through 1.0.6 allows a Subscriber to inject script into affected output. The script executes when another user interacts with that output and can act within the victim's browser session.
| Safe version |
|
||
|---|---|---|---|
| Aug 31, 2026 |
CVE-2026-81778
Kalles Addons permits Subscriber-level XSS
Kalles Addons through 1.0.6 allows a Subscriber to inject script into affected output. The script executes when another user interacts with that output and can act within the victim's browser session.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Aug 25, 2026 |
CVE-2026-78572
Kalles Addons permits unauthenticated PHP object injection
Kalles Addons through 1.0.6 deserializes untrusted input, allowing an unauthenticated attacker to inject a PHP object. The plugin does not supply a known POP chain itself, but a usable chain in another installed plugin or theme can enable arbitrary file deletion, sensitive-data retrieval, or code execution.
|
See mitigation notes |
CVE8.1
NVDPending
|
| Aug 19, 2026 |
CVE-2026-73389
Kalles Addons: Code execution
Kalles Addons is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is n/a through 1.0.6.
|
See mitigation notes |
CVE9.8
NVDPending
|