Sydney
Sydney has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 5.3, and the most serious one scores 5.3 out of 10.
The most common weakness is Missing Authorization, behind 1 of the records (100%).
The one issue recorded for Sydney has a vendor fix available, so running the current release closes it.
All of these findings were reported by Dmitrii Ignatyev. Sydney is installed on roughly 80,000 WordPress sites, so each unpatched flaw has a wide blast radius.
CVE-2025-8999Sydney <= 2.56 - Missing Authorization to Authenticated (Subscriber+) Limited Theme Options Update
Read the full analysisVulnerability Records

Sydney
Author
aThemes
Sydney is a fast, highly customizable WordPress theme for businesses, freelancers, and creative portfolios that want a professional online presence. It works with both Elementor and the WordPress block editor and includes a library of block patterns for building pages fast. Sydney gives you full design control: all Google Fonts, color and layout options, logo upload, a full-screen slider, header images, and sticky navigation. It's responsive, translation- and RTL-ready, WooCommerce-compatible, and built with clean, SEO-friendly code. With 80,000+ active installs and a 4.9-star rating from 750+ reviews, Sydney is a trusted choice for company and portfolio sites. Start fast by importing a ready-made demo: https://athemes.com/sydney-demos/
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C