Bard
Bard has 3 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2025; 2 are fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 4.9, and the most serious one scores 6.1 out of 10. 2024 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (33%). Other recurring categories include Cross-Site Scripting, Missing Authorization.
2 of the records (67%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2025.
3 independent researchers contributed these findings, one record each. Bard is installed on roughly 9,000 WordPress sites, so each unpatched flaw has a wide blast radius.
CVE-2025-63018Bard <= 2.229 - Missing Authorization
Read the full analysisVulnerability Records

Bard
Author
WP Royal
Personal and Multi-Author Free WordPress Blog Theme. Perfect for personal, lifestyle, health & fitness, food, cooking, bakery, travel, beauty, fashion, wedding, photography, news, quotes blog, auto blog, small business website and any other kind of amazing blogs. Minimal, elegant & mobile friendly layout with WooCommerce shop (storefront) support will WOW and inspire your visitors. Well documented and very easy to use even for WordPress beginners. Clean and Modern Responsive design will perfectly showcase your content on any device, even on tablet, mobile & retina displays. Very fast, compatibility with many popular plugins & of course translation & RTL (right to left language) ready, coded with best SEO practices. The theme has features like Text & Image logo, Fullscreen Slider, Header image, Instagram slider widget support, footer menu support, GDPR compatibility plugins support and many more. Works perfectly with all major drag and drop page builders like Elementor, Beaver Builder, Visual Composer, SiteOrigin, Divi. You just need to write and be awesome! TEMPLATE DEMO: http://bard-free.wp-royal-themes.com/demo/
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C