Koji

Koji has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it remains unpatched as of August 2026. Their average CVSS score is 5.3, and the most serious one scores 5.3 out of 10.

The most common weakness is Missing Authorization, behind 1 of the records (100%).

The one issue recorded for Koji has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2026.

All of these findings were reported by Trương Hữu Phúc. Koji is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius.

Strategic Overview

Avg CVSSMedium
5.3/ 10
Patch Coverage0%
Open

1

Fixed

0

Get automatic notifications for all Koji vulnerabilities before they are exploited.

Most severe open issueCVSS 5.3CVE-2026-74020

Koji <= 2.2.1 - Missing Authorization

Read the full analysis

Vulnerability Records

1 records
Showing 1–1 of 1 reports
Koji screenshot
Latestv2.2.1
4.9(11)
98/100
Last Updated
2026-08-05 (20d ago)
Active Installs
1,000+
Downloads
114,164
Requires WP
0+
Requires PHP
5.4+
Created
2018-10-05 (8y ago)

Koji is a clean and lightweight theme for bloggers. It features a masonry grid on the archive pages, a beautiful and minimal design, Block Editor/Gutenberg support, widget areas in the sidebar and the footer, infinite scroll loading that can be set to load more posts on button click or when the visitor reaches the bottom of the page, settings for what post meta to display on archive pages and on single posts, icon links to social media pages, custom logo support, a search overlay that can be accessed from any page, and much more. Demo: https://koji.andersnoren.se

Tags
BlogPortfolioCustom logoGrid layoutPhotographySticky postTwo columnsWide blocksBlock editor stylesEditor styleLeft sidebarTheme optionsFooter widgetsFeatured imagesCustom backgroundThreaded commentsTranslation ready

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C