Mantra
Mantra has one disclosed vulnerability in the WordSec catalog, all reported in 2024; it is fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Mantra has a vendor fix available, so running the current release closes it.
All of these findings were reported by stealthcopter. Mantra is installed on roughly 5,000 WordPress sites, so each unpatched flaw has a wide blast radius.
CVE-2024-44056Mantra <= 3.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Mantra
Author
CryoutCreations
Mantra is a do-it-yourself WordPress theme, featuring a pack of over 100 customization options and easy to use tweaks capable of tuning WordPress to your very specific needs and likes. With the help of a simple and efficient user interface you can customize everything:the layout (1,2 or 3 columns), total and partial site widths, colors (all texts, links, backgrounds etc.), fonts (over 35 font-families plus all Google Fonts), text and header sizes, post metas, post excerpts, post formats, header and background images, custom menus, 27 social media links and icons, pins, bullets and much much more. With a fully responsive layout,a customizable showcase presentation page, animated slider, magazine and blog layouts, 8 widget areas, modern graphics and an easy and intuitive admin section, you can start creating your dream site right now.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C