Colibri WP
Colibri WP has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2024; all 2 are fixed as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10. 2024 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (50%). Other recurring categories include Missing Authorization.
Every one of the 2 issues recorded for Colibri WP has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. Colibri WP is installed on roughly 50,000 WordPress sites, so each unpatched flaw has a wide blast radius.
CVE-2024-33686ColibriWP Theme framework <= (Various Versions) - Missing Authorization
Read the full analysisVulnerability Records

Colibri WP
Author
Extend Themes
A beautiful, very customizable, multipurpose theme that you can use to create amazing websites through drag and drop. It comes with a pre-designed home page, 5 header designs and over 35 ready-to-use content blocks that you can easily customize. You can also design your own custom blocks by combining more than 25 drag and drop components. It offers lots of customization options (video background, slideshow background, header content types, etc) to help you create a website that stands out in no time. It is also designed with responsiveness, to work on mobile devices right out of the box. It is the only theme you will ever need! CHECK OUT THE DEMOS: https://colibriwp.com/go/demos
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C