Opstore
Opstore has 4 disclosed vulnerabilities in the WordSec catalog, reported between 2021 and 2025; 3 are fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 9.1, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 3 high. 2022 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (25%). Other recurring categories include Missing Authorization, PHP Remote File Inclusion.
3 of the records (75%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2025.
3 independent researchers contributed these findings, most of them (2) reported by R3N0. Opstore is installed on roughly 100 WordPress sites, so each unpatched flaw has a wide blast radius. The upstream project has not shipped an update in about 3 years, so new fixes are unlikely to arrive on their own.
CVE-2025-39387Opstore <= 1.4.5 - Unauthenticated Local File Inclusion
Read the full analysisVulnerability Records

Opstore
Author
wpoperations
Opstore is complete perfect WordPress theme for E-Commerce,Shops and Small E-Business Websites. The Theme is fully compatible with Elementor Drag and Drop Builder Plugin so that you can easily create your website as perfered Layout. The Theme has other extra features such as Multiple Header Option,Sidebar Options,Unlimited Color options,Custom Widgets and Many More. Theme is carefully designed to focus the need and features for ecommerce websites.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C