Vireo

Vireo has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.

The most common weakness is Missing Authorization, behind 1 of the records (100%).

The one issue recorded for Vireo has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.

All of these findings were reported by Rooting. Vireo is installed on roughly 800 WordPress sites, so each unpatched flaw has a wide blast radius.

Strategic Overview

Avg CVSSMedium
4.3/ 10
Patch Coverage0%
Open

1

Fixed

0

Get automatic notifications for all Vireo vulnerabilities before they are exploited.

Most severe open issueCVSS 4.3CVE-2025-62751

Vireo <= 1.0.24 - Missing Authorization

Read the full analysis

Vulnerability Records

1 records
2025-12-31 00:00CVE-2025-62751
4.3
Medium
RootingNo
Showing 1–1 of 1 reports
Vireo screenshot
Latestv1.0.37
0.0(0)
0/100
Last Updated
2026-08-17 (28d ago)
Active Installs
800+
Downloads
26,253
Requires WP
5.8+
Requires PHP
7.1+
Created
2024-08-14 (2y ago)

Vireo is an innovative, easily customizable, multi-purpose theme, focused on empowering users to build astonishing WordPress websites. Vireo is mainly designed for small businesses, startups, or personal portfolio websites and works perfectly with Kubio Page Builder which enriches the WordPress block editor with a variety of new blocks and advanced styling options to give you full design freedom.

Tags
PortfolioOne columnCustom logoCustom menuGrid layoutTwo columnsCustom headerEntertainmentTheme optionsFood & drinkFeatured imagesThreaded commentsTranslation readyFull width template

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C