Rarathemes develops a focused portfolio of WordPress themes oriented toward small business, education, and landing-page use cases, including products such as Benevolent, Book Landing Page, and Business One Page. The vendor's vulnerabilities cluster around web-application input-handling and authorization gaps characteristic of theme development, with recurring weaknesses in cross-site scripting, cross-site request forgery, missing authorization checks, and unrestricted file uploads. Current severity, exploitation, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rarathemes over time
Signals from CVEs in this vendor scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-37450HIGH Cross-Site Request Forgery (CSRF) vulnerability in raratheme Benevolent benevolent allows Cross Site Request Forgery.This issue affects Benevolent: from n/a through <= 1.3.4. | Jan 2, 2025 | 8.8 | 24 | NO | NO |
CVE-2024-37230HIGH Cross-Site Request Forgery (CSRF) vulnerability in Rara Theme Book Landing Page.This issue affects Book Landing Page: from n/a through 1.2.3. | Jun 21, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-37937HIGH Cross-Site Request Forgery (CSRF) vulnerability in raratheme Rara Business rara-business allows Cross Site Request Forgery.This issue affects Rara Business: from n/a through <= 1.2 | Jan 2, 2025 | 8.8 | 23 | NO | NO |
CVE-2024-37508HIGH Cross-Site Request Forgery (CSRF) vulnerability in raratheme Construction Landing Page construction-landing-page allows Cross Site Request Forgery.This issue affects Construction L | Jan 2, 2025 | 8.8 | 23 | NO | NO |
CVE-2024-37503HIGH Cross-Site Request Forgery (CSRF) vulnerability in raratheme Lawyer Landing Page lawyer-landing-page allows Cross Site Request Forgery.This issue affects Lawyer Landing Page: from | Jan 2, 2025 | 8.8 | 23 | NO | NO |
CVE-2024-37451HIGH Cross-Site Request Forgery (CSRF) vulnerability in raratheme Travel Agency travel-agency allows Cross Site Request Forgery.This issue affects Travel Agency: from n/a through <= 1.4 | Jan 2, 2025 | 8.8 | 23 | NO | NO |
CVE-2024-37435HIGH Cross-Site Request Forgery (CSRF) vulnerability in raratheme Perfect Portfolio perfect-portfolio allows Cross Site Request Forgery.This issue affects Perfect Portfolio: from n/a th | Jan 2, 2025 | 8.8 | 23 | NO | NO |
CVE-2022-29451HIGH Cross-Site Request Forgery (CSRF) leading to Arbitrary File Upload vulnerability in Rara One Click Demo Import plugin <= 1.2.9 on WordPress allows attackers to trick logged-in admi | Apr 29, 2022 | 8.8 | 22 | NO | NO |
CVE-2025-23998MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in raratheme UltraLight the-ultralight allows Reflected XSS.This issue affects Ul | Jan 21, 2025 | 6.1 | 18 | NO | NO |
CVE-2023-24404MEDIUM Reflected Cross-Site Scripting (XSS) vulnerability in VryaSage Marketing Performance plugin <= 2.0.0 versions. | Apr 23, 2023 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (19 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rarathemes.
Media articles that mention a CVE ID that affects a product developed by Rarathemes — matched by CVE ID, not by vendor name.