VW Storefront
VW Storefront has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.
The most common weakness is Missing Authorization, behind 1 of the records (100%).
The one issue recorded for VW Storefront has a vendor fix available, so running the current release closes it.
All of these findings were reported by Peter Thaleikis. VW Storefront is installed on roughly 200 WordPress sites, so each unpatched flaw has a wide blast radius.
CVE-2024-13686VW Storefront <= 0.9.9 - Missing Authorization to Authenticated (Subscriber+) Settings Reset
Read the full analysisVulnerability Records

VW Storefront
Author
VW THEMES
VW Storefront is a versatile, feature-rich theme designed for creating dynamic online stores and eCommerce sites, focusing on the needs of various businesses such as fashion shops, bookstores, gadget outlets, and more. This lightweight and streamlined theme integrates seamlessly with WooCommerce, making it easy to set up and sell products through your e-shop. The elegant layout captures audience attention with its pixel-perfect, retina-ready design, and its Bootstrap framework allows you to customize the look of your online store to reflect your brand. With secure and optimized code for SEO, your site will perform excellently across all devices, including computers, tablets, and smartphones. It includes numerous features like shortcodes, Hero content, Product Slider, custom widgets, and interactive Call To Action (CTA) buttons, all designed to enhance user experience. Additionally, VW Storefront comes equipped with documentation, social sharing options, and plugins, providing you with everything needed to establish an outstanding eCommerce presence. You can explore more at their demo: https://www.vwthemes.net/vw-storefront-pro/.Demo: https://www.vwthemes.net/vw-storefront-pro/
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C