Airin Blog
Airin Blog has one disclosed vulnerability in the WordSec catalog, all reported in 2024; it is fixed as of September 2026. Their average CVSS score is 9.8, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 0 high.
The most common weakness is Deserialization Of Untrusted Data, behind 1 of the records (100%).
The one issue recorded for Airin Blog has a vendor fix available, so running the current release closes it.
All of these findings were reported by Kévin Mosbahi (Mika). Airin Blog is installed on roughly 300 WordPress sites, so each unpatched flaw has a wide blast radius.
CVE-2024-52413Airin Blog <= 1.6.2 - Unauthenticated PHP Object Injection
Read the full analysisVulnerability Records

Airin Blog
Author
DMC
Airin Blog - is a Multipurpose, responsive, fast, minimal magazine theme for blogs and article sites, news and media, with many settings for all occasions. Modern minimalism combined with versatility and adaptability. Lots of customization options that will provide endless options for creating a unique site. Flexible functionality - different sidebar orientation, flexible header with logo, 4 menu locations, main menu (mega menu), three pagination options, breadcrumbs, author block and related posts. Powerful Typography - Change font size and line height, choose fonts, add color typography for posts and pages. Clean code, no frameworks, full support for the WordPress visual customizer. Speed, adaptability and modularity. A minimum of scripts for modules to work. Decide for yourself which modules will work. SEO optimization with correct titles and markup. Adaptation for WooCommerce, Elementor, bbPress, Events Calendar, Jetpack, WPML. Watch full demos here - web-zone.org/airin-blog
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C