theme

Woostify Vulnerabilities

6 known security issues reported for the Woostify WordPress theme. Most recent disclosed Apr 27, 2026.

1 high 2 medium

Running Woostify on your site? Check whether your installed version is affected.

Scan your site free

Woostify <= 2.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Lity.js Library via data-lity Attribute in Custom HTML Block

medium

The Woostify plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.5.0 This is due to insufficient input sanitization and output escaping in the bundled Lity.js lightbox library, where user-controlled input from the href attribute is concatenated directly into a jQuery HT...

CVSS:
6.4
Affected:
up to 2.5.0
Fixed in:
2.5.1
Disclosed:
Apr 27, 2026

CVE-2026-4805 on NVD →

Woostify <= 2.4.2 - Authenticated (Shop manager+) Stored Cross-Site Scripting

medium

The Woostify theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with shop manager-level access and above, to inject arbitrary web scripts in pages that wi...

CVSS:
4.4
Affected:
up to 2.4.2
Fixed in:
2.5.0
Disclosed:
Sep 26, 2025

CVE-2025-60101 on NVD →

Woostify <= 1.9.1 - Cross-Site Request Forgery

high

The Woostify Theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.9.1. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to add products and edit product quantities in a cart via a forged request...

CVSS:
8.8
Affected:
up to 1.9.1
Fixed in:
1.9.2
Disclosed:
Jun 30, 2021

Woostify [woostify] < 1.9.2

unknown

The Woostify Theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.9.1. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to add products and edit product quantities in a cart via a forged request...

Affected:
up to 1.9.2
Fixed in:
1.9.2
Disclosed:
Jun 30, 2021

Woostify [woostify] < 1.9.2

unknown

The theme did not properly check for CSRF, allowing attackers to bypass them and make logged in users add products and edit quantity in their checkout basket

Affected:
up to 1.9.2
Fixed in:
1.9.2

Woostify [woostify] <= 2.4.2 (unfixed)

unknown
Affected:
up to 2.4.2
Fix:
No patched version reported

CVE-2025-60101 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database