Spark Multipurpose
Spark Multipurpose has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Spark Multipurpose has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by Peter Thaleikis. Spark Multipurpose is installed on roughly 40 WordPress sites, so each unpatched flaw has a wide blast radius. The upstream project has not shipped an update in about 2 years, so new fixes are unlikely to arrive on their own.
CVE-2025-50030Spark Multipurpose <= 1.0.7 - Authenticated (Contributor+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Spark Multipurpose
Author
Sparkle WP
The Spark Multipurpose is a classic, simple, clean, and versatile WordPress theme. It’s a fully responsive design with all major browsers compatible, and it’s included multiple premade, designed demos for all kinds of businesses so that you can use it for any kind of webpage. Spark Multipurpose is versatile and flexible, and it’s designed to serve a wide range of websites and for a wide range of businesses. You can create business websites, portfolio websites, blogs, e-commerce stores, any agency websites, and more with 0 lines of code. For more support visit https://sparklewpthemes.com/support/
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C