Mvpthemes develops a narrow portfolio of WordPress-based themes and plugins, including products such as Zoxpress, Click Mag, and Zox News, that extend site functionality and presentation. The observed vulnerability signal centers on missing authorization weaknesses, a characteristic gap in access-control enforcement within theme and plugin codebases. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mvpthemes over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-13653HIGH The ZoxPress - The All-In-One WordPress News Theme theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing cap | Feb 12, 2025 | 8.8 | 24 | NO | NO |
CVE-2024-13656HIGH The Click Mag - Viral WordPress News Magazine/Blog Theme theme for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missin | Feb 12, 2025 | 8.1 | 23 | NO | NO |
CVE-2024-13654HIGH The ZoxPress - The All-In-One WordPress News Theme theme for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capa | Feb 12, 2025 | 8.1 | 22 | NO | NO |
CVE-2024-11936HIGH The Zox News theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'backup_options' | Jan 26, 2025 | 8.8 | 21 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mvpthemes.
Media articles that mention a CVE ID that affects a product developed by Mvpthemes — matched by CVE ID, not by vendor name.