Pliska
Pliska has one disclosed vulnerability in the WordSec catalog, all reported in 2024; it is fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Pliska has a vendor fix available, so running the current release closes it.
All of these findings were reported by stealthcopter. Pliska is installed on roughly 600 WordPress sites, so each unpatched flaw has a wide blast radius.
CVE-2024-33954Pliska <= 0.3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Author Display Name
Read the full analysisVulnerability Records

Pliska
Author
Atanas Yonkov
Pliska is a beautiful, next-generation WordPress theme with powerful theme options. It is designed for creating high quality blogs, multi-author publishing platforms, portfolio and company websites. It is fully customizable, with lots of features, looks great and behaves flowlessly on any device, screen size and browser. This modern theme features ready-to-use block patterns, with which you can create your new website in minutes. The theme is optimized for speed and SEO. It features Schema.org markup and is WCAG 2.0 (Level AA) compliant. Make your site truely unique with three different page layouts, different header options, Google fonts and take advantage of all the other awesome free features such as social share for posts, author box, related posts, different menu positions and mega menu functionality. Another awesome feature is that site visitors can switch between light and dark mode with a single click. The theme is fully compatible with Gutenberg but also supports the good old classic editor. It also provides a seemless integration with all the popular page builders. Support for WooCommerce and popular WordPress plugins is also fully guarantied. Theme demo: https://try-pliska.nasiothemes.com/
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C