Nayrathemes is a theme and plugin vendor with a focused product portfolio centered on the Clever Fox offering, primarily supporting WordPress and related web-building platforms. The vendor's disclosed vulnerabilities cluster around web application input-handling and access-control weaknesses, including cross-site scripting and missing authorization checks, which are characteristic of theme and plugin codebases exposed to user-generated content. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nayrathemes over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-6876MEDIUM The Clever Fox – One Click Website Importer by Nayra Themes plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'clever | Jun 7, 2024 | 5.4 | 18 | NO | NO |
CVE-2024-1768MEDIUM The Clever Fox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's info box block in all versions up to, and including, 25.2.0 due to insufficient in | Jun 7, 2024 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nayrathemes.
Media articles that mention a CVE ID that affects a product developed by Nayrathemes — matched by CVE ID, not by vendor name.