Calliope
Calliope has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2024; all 2 are fixed as of August 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10. 2024 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (50%). Other recurring categories include Missing Authorization.
Every one of the 2 issues recorded for Calliope has a vendor fix available, so running the current release closes all known holes.
All of these findings were reported by Dhabaleshwar Das. Calliope is installed on roughly 4,000 WordPress sites, so each unpatched flaw has a wide blast radius.
CVE-2024-33686ColibriWP Theme framework <= (Various Versions) - Missing Authorization
Read the full analysisVulnerability Records

Calliope
Author
Extend Themes
colibri-wpCalliope is a beautiful, very customizable, multipurpose theme that you can use to create amazing websites through drag and drop. It comes with a pre-designed home page, 5 header designs and over 35 ready-to-use content blocks that you can easily customize. You can also design your own custom blocks by combining more than 25 drag and drop components. Calliope offers lots of customization options (video background, slideshow background, header content types, etc) to help you create a website that stands out in no time. It is also designed with responsiveness, to work on mobile devices right out of the box. Calliope is the only theme you will ever need! CHECK OUT THE DEMOS: https://colibriwp.com/go/calliope-demos
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C