Generally speaking outdated plugins are more of a risk, but themes should be updated.
The "heavier" the theme (more javascript, custom functions etc) the more likely it is to become a risk when out of date. Frankly it\'s one good reason to code lean/mean themes yourself and not buy of the shelf, but that\'s just my opinion.
The answer to your question then, yes is "It\'s a risk". But I wouldn\'t not go as far as as saying "significant" (as opposed to the plugins)