SpicePress
SpicePress has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it remains unpatched as of August 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for SpicePress has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2026.
All of these findings were reported by Trương Hữu Phúc (truonghuuphuc). SpicePress is installed on roughly 3,000 WordPress sites, so each unpatched flaw has a wide blast radius.
CVE-2026-39621SpicePress <= 2.3.2.5 - Cross-Site Request Forgery
Read the full analysisVulnerability Records

SpicePress
Author
spicethemes
SpicePress is a responsive, modern, and highly customizable WordPress business theme built to create professional websites with ease. It is suitable for corporate websites, creative agencies, startups, freelancers, restaurants, wedding planners, law firms, consulting firms, travel agencies, photography portfolios, blogs, and WooCommerce-powered online stores.The theme includes ready-to-use starter sites, allowing you to import professionally designed demo layouts and launch your website within minutes. These starter sites can be previewed and imported directly from a dedicated starter site panel, making the setup process fast and beginner-friendly.SpicePress offers a powerful yet easy-to-use customization experience through the WordPress Customizer, enabling you to control layouts, colors, typography, and content without writing any code. The theme is translation-ready and fully compatible with popular plugins such as WooCommerce, WPML, Polylang, and Contact Form 7, making it suitable for multilingual and business-focused websites.SpicePress is GDPR-compliant and does not rely on external Google Fonts. All fonts are hosted locally to ensure improved performance, better privacy, and compliance with modern web standards.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C