Koji
Koji has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it remains unpatched as of August 2026. Their average CVSS score is 5.3, and the most serious one scores 5.3 out of 10.
The most common weakness is Missing Authorization, behind 1 of the records (100%).
The one issue recorded for Koji has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2026.
All of these findings were reported by Trương Hữu Phúc. Koji is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius.
CVE-2026-74020Koji <= 2.2.1 - Missing Authorization
Read the full analysisVulnerability Records

Koji is a clean and lightweight theme for bloggers. It features a masonry grid on the archive pages, a beautiful and minimal design, Block Editor/Gutenberg support, widget areas in the sidebar and the footer, infinite scroll loading that can be set to load more posts on button click or when the visitor reaches the bottom of the page, settings for what post meta to display on archive pages and on single posts, icon links to social media pages, custom logo support, a search overlay that can be accessed from any page, and much more. Demo: https://koji.andersnoren.se
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C