Customify

Customify has one disclosed vulnerability in the WordSec catalog, all reported in 2023; it is fixed as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).

The one issue recorded for Customify has a vendor fix available, so running the current release closes it.

All of these findings were reported by Kévin Mosbahi (Mika). Customify is installed on roughly 10,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

Strategic Overview

Avg CVSSMedium
4.3/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Customify vulnerabilities before they are exploited.

Highest severity on recordCVSS 4.3CVE-2023-27633

Customify <= 2.10.4 - Cross-Site Request Forgery to Settings Update

Read the full analysis

Vulnerability Records

1 records
Customify banner
Latestv2.10.9
3.8(9)
76/100
Last Updated
2026-08-13 (1mo ago)
Active Installs
10,000+
Downloads
716,518
Requires WP
5.9.0+
Requires PHP
7.4+
Tested up to
WP 7.1
Created
2015-02-16 (12y ago)

With Customify, developers can easily create advanced theme-specific options inside the WordPress Customizer. Using those options, a user can make presentational changes without having to know or edit the theme code. This plugin is primarily intended to be used together with Pixelgrade themes. So the best way to get acquainted with it’s capabilities is to study the way one of Pixelgrade’s themes integrates with it. Made with care by Pixelgrade Credits Select2 JavaScript library – License: MIT CSSOM.js JavaScript library – License: MIT Ace Editor JavaScript editor – License: BSD jQuery React JavaScript jQuery plugin – License: MIT Web Font Loader JavaScript library – License: Apache 2.0 Fuse.js Lightweight fuzzy-search JavaScript library – License: Apache 2.0 Default image for Style Manager Color Palette control – License: Unsplash

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C