Ona
Ona has 3 disclosed vulnerabilities in the WordSec catalog, reported between 2023 and 2026; all 3 are fixed as of August 2026. Their average CVSS score is 6.4, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 1 high. 2026 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Scripting, behind 1 of the records (33%). Other recurring categories include Server-Side Request Forgery (SSRF), Unrestricted Upload Of File With Dangerous Type.
Every one of the 3 issues recorded for Ona has a vendor fix available, so running the current release closes all known holes.
3 independent researchers contributed these findings, one record each. Ona is installed on roughly 2,000 WordPress sites, so each unpatched flaw has a wide blast radius.
CVE-2026-32482Ona < 1.24 - Authenticated (Subscriber+) Arbitrary File Upload
Read the full analysisVulnerability Records

Ona is a Full Site Editing WordPress theme based on the minimal design style. It comes with many pre-defined block patterns and color scheme styles. Ona includes 18 child themes, 12 of them are free. Header and footer builder allows you easily edit your layout and choose pre-made elements. It's easy to customize colors and fonts via global options. This theme scores 98 on mobile and it is perfect for fast optimized websites that have an instant impact On Core Web Vitals performance. ★ Demo: https://ona.deothemes.com ★
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C