← WordPress Vulnerabilities
WordPress security by component

capella

capella is a WordPress theme with 3 published CVE records in this archive. The latest tracked vulnerability was published Aug 20, 2026; the highest published CVSS base score is 9.8.

Theme slug: capella

CVE-2025-15689: Capella permits unauthenticated privilege escalation

Capella <= 2.5.5 allows an unauthenticated attacker to cross a privilege boundary. Its CVSS vector assigns high confidentiality, integrity and availability impact, consistent with a site-compromise outcome.

PublishedAug 20, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for capella
Safe version
Aug 20, 2026 CVE-2025-15689
Capella permits unauthenticated privilege escalation
Capella <= 2.5.5 allows an unauthenticated attacker to cross a privilege boundary. Its CVSS vector assigns high confidentiality, integrity and availability impact, consistent with a site-compromise outcome.
See mitigation notes
CVE9.8
NVDPending
Aug 20, 2026 CVE-2025-15688
Capella permits unauthenticated SQL injection
Capella <= 2.5.5 allows an unauthenticated attacker to place crafted input into an SQL query without adequate neutralization. The CVSS vector assigns high confidentiality and low availability impact, indicating database disclosure and query disruption without a separately claimed write primitive.
See mitigation notes
CVE9.3
NVDPending
Feb 20, 2026 CVE-2025-69370
Capella: Code execution
Capella is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE9.8
NVDPending