WordPress security by component
capella
capella is a WordPress theme with 3 published CVE records in this archive. The latest tracked vulnerability was published Aug 20, 2026; the highest published CVSS base score is 9.8.
Theme slug:
capellaLatest vulnerability
CVE-2025-15689: Capella permits unauthenticated privilege escalation
Capella <= 2.5.5 allows an unauthenticated attacker to cross a privilege boundary. Its CVSS vector assigns high confidentiality, integrity and availability impact, consistent with a site-compromise outcome.
| Safe version |
|
||
|---|---|---|---|
| Aug 20, 2026 |
CVE-2025-15689
Capella permits unauthenticated privilege escalation
Capella <= 2.5.5 allows an unauthenticated attacker to cross a privilege boundary. Its CVSS vector assigns high confidentiality, integrity and availability impact, consistent with a site-compromise outcome.
|
See mitigation notes |
CVE9.8
NVDPending
|
| Aug 20, 2026 |
CVE-2025-15688
Capella permits unauthenticated SQL injection
Capella <= 2.5.5 allows an unauthenticated attacker to place crafted input into an SQL query without adequate neutralization. The CVSS vector assigns high confidentiality and low availability impact, indicating database disclosure and query disruption without a separately claimed write primitive.
|
See mitigation notes |
CVE9.3
NVDPending
|
| Feb 20, 2026 |
CVE-2025-69370
Capella: Code execution
Capella is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE9.8
NVDPending
|