CoziPress
CoziPress has one disclosed vulnerability in the WordSec catalog, all reported in 2024; it remains unpatched as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for CoziPress has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2024.
All of these findings were reported by stealthcopter. CoziPress is installed on roughly 900 WordPress sites, so each unpatched flaw has a wide blast radius.
CVE-2024-38786CoziPress <= 1.0.32 - Authenticated (Contributor+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

CoziPress
Author
BurgerThemes
CoziPress is a Modern Multipurpose Business theme for Agency, Business, Finance, Consulting, Factory, Real Estate, Construction, Cleaning Service, Startup or any other individual website due to its adaptability. It looks perfect on all modern browsers, mobile, tablets, and any device, Theme is full of customization options and settings, you can change almost everything. CoziPress provides unique layouts Such as Service, Team, About, Gallery, Blog Pages, Shop Pages, Pricing Pages, Contact Page, Coming Soon, Careers Page, and many more. If you are a lover of creative designs and would like to build a very unique and professional website quickly then your search should end at CoziPress. Checkout Pro Version https://burgerthemes.com/demo/pro/cozipress/
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C