Climaxthemes develops a focused line of web themes and related products, primarily Kata and Kata Plus, where the vulnerability signal centers on input-handling issues in web page generation such as cross-site scripting. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Climaxthemes over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-32572CRITICAL Deserialization of Untrusted Data vulnerability in Climax Themes Kata Plus kata-plus allows Object Injection.This issue affects Kata Plus: from n/a through <= 1.5.3. | Apr 17, 2025 | 9.8 | 29 | NO | NO |
CVE-2023-2813MEDIUM All of the above Aapna WordPress theme through 1.3, Anand WordPress theme through 1.2, Anfaust WordPress theme through 1.1, Arendelle WordPress theme before 1.1.13, Atlast Business | Sep 4, 2023 | 6.1 | 25 | NO | YES |
CVE-2025-50009MEDIUM Missing Authorization vulnerability in Climax Themes Kata Plus kata-plus allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kata Plus: from | Jun 20, 2025 | 5.4 | 17 | NO | NO |
CVE-2024-50501MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Climax Themes Kata Plus kata-plus allows DOM-Based XSS.This issue affects Kata | Oct 28, 2024 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Climaxthemes.
Media articles that mention a CVE ID that affects a product developed by Climaxthemes — matched by CVE ID, not by vendor name.