Delicate
Delicate has one disclosed vulnerability in the WordSec catalog, all reported in 2024; it remains unpatched as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Delicate has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2024.
All of these findings were reported by Francesco Carlucci. Delicate is installed on roughly 500 WordPress sites, so each unpatched flaw has a wide blast radius. The upstream project has not shipped an update in about 13 years, so new fixes are unlikely to arrive on their own.
CVE-2024-5867Delicate <= 3.5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button Shortcode
Read the full analysisVulnerability Records

Delicate
Author
nattywp
Delicate is a resposive and highly customizable lightweight theme, designed to make your blog works on mobile devices and the endless number of desktop screen resolutions. With Delicate you can adjust Color scheme, display Page-based Slideshow or Header image, style your page content with additional Shortcodes, change Slideshow effects and control Transition speed. This is a free professional WordPress theme built on the NattyWP CMS Framework.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C