SpicePress

SpicePress has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it remains unpatched as of August 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).

The one issue recorded for SpicePress has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2026.

All of these findings were reported by Trương Hữu Phúc (truonghuuphuc). SpicePress is installed on roughly 3,000 WordPress sites, so each unpatched flaw has a wide blast radius.

Strategic Overview

Avg CVSSMedium
4.3/ 10
Patch Coverage0%
Open

1

Fixed

0

Get automatic notifications for all SpicePress vulnerabilities before they are exploited.

Most severe open issueCVSS 4.3CVE-2026-39621

SpicePress <= 2.3.2.5 - Cross-Site Request Forgery

Read the full analysis

Vulnerability Records

1 records
SpicePress screenshot
Latestv3.8.2
4.8(48)
96/100
Last Updated
2026-04-17 (4mo ago)
Active Installs
3,000+
Downloads
745,084
Requires WP
4.5+
Requires PHP
5.4+
Created
2018-04-19 (8y ago)

SpicePress is a responsive, modern, and highly customizable WordPress business theme built to create professional websites with ease. It is suitable for corporate websites, creative agencies, startups, freelancers, restaurants, wedding planners, law firms, consulting firms, travel agencies, photography portfolios, blogs, and WooCommerce-powered online stores.The theme includes ready-to-use starter sites, allowing you to import professionally designed demo layouts and launch your website within minutes. These starter sites can be previewed and imported directly from a dedicated starter site panel, making the setup process fast and beginner-friendly.SpicePress offers a powerful yet easy-to-use customization experience through the WordPress Customizer, enabling you to control layouts, colors, typography, and content without writing any code. The theme is translation-ready and fully compatible with popular plugins such as WooCommerce, WPML, Polylang, and Contact Form 7, making it suitable for multilingual and business-focused websites.SpicePress is GDPR-compliant and does not rely on external Google Fonts. All fonts are hosted locally to ensure improved performance, better privacy, and compliance with modern web standards.

Tags
E commerceOne columnCustom logoCustom menuSticky postTwo columnsEditor styleRight sidebarFooter widgetsFeatured imagesThreaded commentsTranslation readyRTL language support

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C