Unlimited
Unlimited has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Unlimited has a vendor fix available, so running the current release closes it.
All of these findings were reported by stealthcopter. Unlimited is installed on roughly 400 WordPress sites, so each unpatched flaw has a wide blast radius.
CVE-2025-31073Unlimited <= 1.45 - Authenticated (Contributor+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Unlimited
Author
Ben Sibley
Fast, responsive, beautiful, and accessible. With Unlimited, your content will reach more people, on more devices, around the world. Unlimited's simple and dark design puts the focus on your content, and supports it with clean, reliable code. Use this minimalist blogging theme to setup a website for a magazine, school, or personal journal. As a free WP theme, you can use Unlimited for as many sites as you want. Unlimited is also fully compatible with the new Gutenberg post editor. Preview Unlimited now on desktop, tablets, and mobile devices with the interactive live demo: https://www.competethemes.com/demos/?theme=unlimited
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C