Arrival
Arrival has 4 disclosed vulnerabilities in the WordSec catalog, reported between 2021 and 2025; 3 are fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 9.1, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 3 high. 2022 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (25%). Other recurring categories include Missing Authorization, PHP Remote File Inclusion.
3 of the records (75%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2025.
3 independent researchers contributed these findings, most of them (2) reported by R3N0. Arrival is installed on roughly 100 WordPress sites, so each unpatched flaw has a wide blast radius.
CVE-2025-32921Arrival <= 1.4.5 - Unauthenticated Local File Inclusion
Read the full analysisVulnerability Records

Arrival
Author
wpoperations
Arrival is complete multipurpose WordPress theme. The theme can be used to create any type of website like corporate, business, portfolio, construction, charity, resturant, landing pages, education, fitness, gym, spa, travel, ecommerce, online stores etc. The theme is lightweight, fast and fully compatible with elementor and other major page builders. The theme comes with fully Gutenberg ready so you are free to edit and publish with new WordPress editor. The theme is a combination of power, freedom, and beauty which means there is no limit of anything you need to create a feature website with your own creative ideas.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C