← WordPress Vulnerabilities
WordPress security by component

Kalles Addons

Kalles Addons (kalles-addons) is a WordPress plugin with 3 published CVE records in this archive. The latest tracked vulnerability was published Aug 31, 2026; the highest published CVSS base score is 9.8.

Plugin slug: kalles-addons

CVE-2026-81778: Kalles Addons permits Subscriber-level XSS

Kalles Addons through 1.0.6 allows a Subscriber to inject script into affected output. The script executes when another user interacts with that output and can act within the victim's browser session.

PublishedAug 31, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for kalles-addons
Safe version
Aug 31, 2026 CVE-2026-81778
Kalles Addons permits Subscriber-level XSS
Kalles Addons through 1.0.6 allows a Subscriber to inject script into affected output. The script executes when another user interacts with that output and can act within the victim's browser session.
See mitigation notes
CVE6.5
NVDPending
Aug 25, 2026 CVE-2026-78572
Kalles Addons permits unauthenticated PHP object injection
Kalles Addons through 1.0.6 deserializes untrusted input, allowing an unauthenticated attacker to inject a PHP object. The plugin does not supply a known POP chain itself, but a usable chain in another installed plugin or theme can enable arbitrary file deletion, sensitive-data retrieval, or code execution.
See mitigation notes
CVE8.1
NVDPending
Aug 19, 2026 CVE-2026-73389
Kalles Addons: Code execution
Kalles Addons is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is n/a through 1.0.6.
See mitigation notes
CVE9.8
NVDPending