Cozythemes develops a suite of WordPress plugins and themes, including products such as Cozy Blocks, BlockBooster, FotaWP, Hello Agency, and ReviveNews, that extend page-building and content management capabilities for small to mid-market publishers and agencies. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and recur through authorization and input-handling weaknesses—missing authorization checks and cross-site scripting flaws—that are characteristic of WordPress plugin ecosystems where authentication boundaries and user input contexts require careful management. Defenders should prioritize patches for this vendor's plugins in WordPress environments and audit content-creation access controls; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cozythemes over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-43980CRITICAL Missing Authorization vulnerability in CozyThemes Fota WP allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fota WP: from n/a through 1.4.1 | Nov 1, 2024 | 9.8 | 29 | NO | NO |
CVE-2024-43341CRITICAL Missing Authorization vulnerability in CozyThemes Hello Agency allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Hello Agency: from n/a through 1.0 | Nov 1, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-43979CRITICAL Missing Authorization vulnerability in CozyThemes Blockbooster allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Blockbooster: from n/a through 1.0 | Nov 1, 2024 | 9.8 | 25 | NO | NO |
CVE-2024-43974CRITICAL Missing Authorization vulnerability in CozyThemes ReviveNews allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects ReviveNews: from n/a through 1.0.2. | Nov 1, 2024 | 9.8 | 25 | NO | NO |
CVE-2024-47355MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CozyThemes Cozy Blocks cozy-addons allows Stored XSS.This issue affects Cozy B | Oct 6, 2024 | 6.5 | 20 | NO | NO |
CVE-2025-59573MEDIUM Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in CozyThemes Cozy Blocks cozy-addons allows Code Injection.This issue affects Cozy Bloc | Sep 22, 2025 | 5.3 | 19 | NO | NO |
CVE-2025-30838MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CozyThemes Cozy Blocks cozy-addons allows Stored XSS.This issue affects Cozy B | Mar 27, 2025 | 6.5 | 19 | NO | NO |
CVE-2024-50502MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CozyThemes Cozy Blocks cozy-addons allows DOM-Based XSS.This issue affects Coz | Oct 28, 2024 | 5.4 | 17 | NO | NO |
CVE-2025-47485MEDIUM Missing Authorization vulnerability in CozyThemes Cozy Blocks cozy-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cozy Blocks: fr | May 7, 2025 | 5.3 | 16 | NO | NO |
CVE-2024-50441MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CozyThemes Cozy Blocks cozy-addons allows Stored XSS.This issue affects Cozy B | Oct 28, 2024 | 5.4 | 16 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cozythemes.
Media articles that mention a CVE ID that affects a product developed by Cozythemes — matched by CVE ID, not by vendor name.