Child Theme Wizard
Child Theme Wizard has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it is fixed as of August 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for Child Theme Wizard has a vendor fix available, so running the current release closes it.
All of these findings were reported by Ananda Dhakal. Child Theme Wizard is installed on roughly 10,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2026-57655Child Theme Wizard <= 1.4 - Cross-Site Request Forgery
Read the full analysisVulnerability Records

Child Theme Wizard
Author
Jay Versluis
The Child Theme Wizard lets you create a new child theme without the need for additional tools, right from within the WordPress admin interface. Once activated you can find it under Tools – Child Theme Wizard. Specify a parent theme, customise options such as title and description and click Create Child Theme. Upon success you will find your new theme under Appearance – Themes. You have the option to include GPL License Terms if you wish. The Wizard will automatically create a thumbnail too. To find out more about child themes and why they are useful, please read the WordPress Developer Docs on Child Themes.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C