Virtue
Virtue has one disclosed vulnerability in the WordSec catalog, all reported in 2024; it is fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Virtue has a vendor fix available, so running the current release closes it.
All of these findings were reported by stealthcopter. Virtue is installed on roughly 10,000 WordPress sites, so each unpatched flaw has a wide blast radius.
CVE-2024-4034Virtue <= 3.4.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Author
Read the full analysisVulnerability Records

Virtue
Author
Nexcess
The Virtue is a classic theme, built before the Gutenberg block editor was created. While some support has been added for the block editor it's a WordPress legacy theme. The theme is extremely versatile with tons of options, easy to customize and loaded with great features. The clean, modern design is built with html5 and css3 and uses the powerful responsive framework from Bootstrap to be a fully responsive and mobile friendly. Virtue has support for wide and fullwidth blocks. It's fully e-commerce (Woocommerce) ready with all the tools you need to design an awesome online store. The versatile design is perfect for any business, online store, portfolio, or personal site. We built Virtue with a powerful options panel where you can set things like your home layout, sliders, custom fonts, and completely customize your look without writing any CSS. You are going to love how easy it is to create using this theme.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C