Orchid Store
Orchid Store has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2026; 1 is fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 4.8, and the most serious one scores 5.3 out of 10.
The most common weakness is Missing Authorization, behind 2 of the records (100%).
1 of the records (50%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2026.
2 independent researchers contributed these findings, one record each. Orchid Store is installed on roughly 5,000 WordPress sites, so each unpatched flaw has a wide blast radius.
CVE-2026-24612Orchid Store <= 1.5.15 - Missing Authorization
Read the full analysisVulnerability Records

Orchid Store
Author
themebeez
Orchid Store is a clean, flexible, stylish & dynamic e-commerce WordPress theme. It is totally based on WooCommerce, WordPress plugin. Orchid Store can be used to build a wide range of online stores ranging from a fashion store, mobile and gadget store, furniture shop, sports shop, home décor store, jewellery store or any kind of multi-category online shop. Orchid Store has adequate built-in features that are required to build an online shop or stores. Orchid Store gives users the flexible customization experience for crafting their online shop with ease. Customization in Orchid Store is so simple that it can easily be tuned from WordPress live customizer. Orchid Store is fully widgetized where one can easily drag & drop widgets to their respective widget areas to display website sections at front-end. If you are looking to extend your online store with the page builder, you can easily do it using Elementor page builder. If you are wondering how Orchid Store looks, please do kindly visit https://themebeez.com/themes/orchid-store/ for live demo preview. Do kindly visit https://themebeez.com/docs/orchid-store-theme-documentation/ if you would need a theme setup documentation guide.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C