Opstore

Opstore has 4 disclosed vulnerabilities in the WordSec catalog, reported between 2021 and 2025; 3 are fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 9.1, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 3 high. 2022 was the busiest year with 2 disclosures.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (25%). Other recurring categories include Missing Authorization, PHP Remote File Inclusion.

3 of the records (75%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2025.

3 independent researchers contributed these findings, most of them (2) reported by R3N0. Opstore is installed on roughly 100 WordPress sites, so each unpatched flaw has a wide blast radius. The upstream project has not shipped an update in about 3 years, so new fixes are unlikely to arrive on their own.

Strategic Overview

Avg CVSSCritical
9.1/ 10
Patch Coverage75%
Open

1

Fixed

3

Get automatic notifications for all Opstore vulnerabilities before they are exploited.

Most severe open issueCVSS 9.8CVE-2025-39387

Opstore <= 1.4.5 - Unauthenticated Local File Inclusion

Read the full analysis

Vulnerability Records

4 records
Opstore screenshot
Latestv1.4.5
4.9(30)
98/100
Last Updated
2023-03-14 (4y ago)
Active Installs
100+
Downloads
82,541
Requires WP
0+
Requires PHP
5.6+
Created
2018-12-12 (8y ago)

Opstore is complete perfect WordPress theme for E-Commerce,Shops and Small E-Business Websites. The Theme is fully compatible with Elementor Drag and Drop Builder Plugin so that you can easily create your website as perfered Layout. The Theme has other extra features such as Multiple Header Option,Sidebar Options,Unlimited Color options,Custom Widgets and Many More. Theme is carefully designed to focus the need and features for ecommerce websites.

Tags
BlogNewsE commerceCustom logoCustom menuSticky postEditor styleLeft sidebarPost formatsCustom headerRight sidebarTheme optionsFooter widgetsFeatured imagesCustom backgroundThreaded commentsTranslation ready

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C