Sydney Toolbox
Sydney Toolbox has 5 disclosed vulnerabilities in the WordSec catalog, all reported in 2024; all 5 are fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10. 2024 was the busiest year with 5 disclosures.
The most common weakness is Cross-Site Scripting, behind 5 of the records (100%).
Every one of the 5 issues recorded for Sydney Toolbox has a vendor fix available, so running the current release closes all known holes.
4 independent researchers contributed these findings, most of them (2) reported by Ngô Thiên An (ancorn_). Sydney Toolbox is installed on roughly 50,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.7.7.
CVE-2024-4473Sydney Toolbox <= 1.31 - Authenticated (Contributor+) Stored Cross-Site Scripting via aThemes: Portfolio Widget
Read the full analysisVulnerability Records
Sydney Toolbox
Author
Syed Balkhi
The Sydney Toolbox plugin is meant to be used only with the Sydney WordPress theme. This plugin registers custom post types and custom fields that are needed in the Sydney theme
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C