← WordPress Vulnerabilities
WordPress security by component

corpkit

corpkit is a WordPress theme with 3 published CVE records in this archive. The latest tracked vulnerability was published Jul 02, 2026; the highest published CVSS base score is 9.9.

Theme slug: corpkit

CVE-2025-69132: Corpkit: Sensitive information exposure

Corpkit is affected by sensitive information exposure. Exploitation requires an authenticated subscriber account. Successful exploitation can disclose data that should not be available to the caller. The published affected range is n/a through 1.0.5.

PublishedJul 02, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for corpkit
Safe version
Jul 02, 2026 CVE-2025-69132
Corpkit: Sensitive information exposure
Corpkit is affected by sensitive information exposure. Exploitation requires an authenticated subscriber account. Successful exploitation can disclose data that should not be available to the caller. The published affected range is n/a through 1.0.5.
See mitigation notes
CVE6.5
NVDPending
Jan 08, 2026 CVE-2025-67925
Corpkit: Filesystem traversal
Corpkit is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE7.5
NVDPending
Jan 08, 2026 CVE-2025-67924
Corpkit: Dangerous file upload
Corpkit is affected by dangerous file upload. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
See mitigation notes
CVE9.9
NVDPending