Hestia

Hestia has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2025; all 2 are fixed as of September 2026. Their average CVSS score is 4.8, and the most serious one scores 5.3 out of 10.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (50%). Other recurring categories include Missing Authorization.

Every one of the 2 issues recorded for Hestia has a vendor fix available, so running the current release closes all known holes.

2 independent researchers contributed these findings, one record each. Hestia is installed on roughly 70,000 WordPress sites, so each unpatched flaw has a wide blast radius.

Strategic Overview

Avg CVSSMedium
4.8/ 10
Patch Coverage100%
Open

0

Fixed

2

Get automatic notifications for all Hestia vulnerabilities before they are exploited.

Highest severity on recordCVSS 5.3CVE-2025-53986

Hestia <= 3.2.10 - Missing Authorization

Read the full analysis

Vulnerability Records

2 records
Hestia screenshot
Latestv3.3.6
4.8(560)
96/100
Last Updated
2026-09-07 (6d ago)
Active Installs
70,000+
Downloads
4,720,460
Requires WP
0+
Requires PHP
5.4.0+
Created
2017-05-19 (9y ago)

Hestia is a modern WordPress theme for professionals. It fits creative business, small businesses (restaurants, wedding planners, sport/medical shops), startups, corporate businesses, online agencies and firms, portfolios, ecommerce (WooCommerce), and freelancers. It has a multipurpose one-page design, widgetized footer, blog/news page and a clean look, is compatible with: Flat Parallax Slider, Photo Gallery, Travel Map and Elementor Page Builder . The theme is responsive, WPML, Retina ready, SEO friendly, and uses Material Kit for design.

Tags
BlogPortfolioE commerceOne columnCustom logoCustom menuGrid layoutSticky postTwo columnsWide blocksEditor styleLeft sidebarPost formatsCustom colorsCustom headerRight sidebarTheme optionsFooter widgetsFeatured imagesFlexible headerCustom backgroundThreaded commentsTranslation readyFull width templateRTL language supportFeatured image header

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C