Square
Square has one disclosed vulnerability in the WordSec catalog, all reported in 2023; it is fixed as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.
The most common weakness is Missing Authorization, behind 1 of the records (100%).
The one issue recorded for Square has a vendor fix available, so running the current release closes it.
All of these findings were reported by Dave Jong. Square is installed on roughly 2,000 WordPress sites, so each unpatched flaw has a wide blast radius.
CVE-2023-30486Square <= 2.0.0 - Missing Authorization via activate_plugin
Read the full analysisVulnerability Records

Square
Author
hashthemes
Square is a modern, fully responsive, and SEO-friendly WordPress theme, ideal for creating business websites, corporate sites, online portfolios, personal blogs, digital agencies, and WooCommerce-powered online stores. Designed with a clean and minimalist layout, Square ensures fast loading times and an excellent user experience across all devices. It is highly customizable through the WordPress Customizer, allowing real-time design changes without touching a single line of code. The theme is compatible with popular plugins like Elementor, WPML, Polylang, bbPress, and BuddyPress, making it suitable for multilingual websites, forums, and online communities. Square also supports retina displays and right-to-left (RTL) languages, ensuring global accessibility. Whether you're building a small business website or a feature-rich eCommerce platform, Square provides all the essential tools, flexibility, and modern design elements needed to launch a professional and engaging WordPress website. For demo https://demo.hashthemes.com/square
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C