Vireo
Vireo has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.
The most common weakness is Missing Authorization, behind 1 of the records (100%).
The one issue recorded for Vireo has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by Rooting. Vireo is installed on roughly 800 WordPress sites, so each unpatched flaw has a wide blast radius.
CVE-2025-62751Vireo <= 1.0.24 - Missing Authorization
Read the full analysisVulnerability Records

Vireo
Author
Extend Themes
Vireo is an innovative, easily customizable, multi-purpose theme, focused on empowering users to build astonishing WordPress websites. Vireo is mainly designed for small businesses, startups, or personal portfolio websites and works perfectly with Kubio Page Builder which enriches the WordPress block editor with a variety of new blocks and advanced styling options to give you full design freedom.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C