CVE · Medium

CVE-2023-6876 — Clever Fox [clever-fox] < 25.2.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-6876 Clever Fox [clever-fox] < 25.2.1 Missing Authorization Medium 5.4 < 25.2.1 25.2.1 2024-06-06

CVE-2023-6876

The Clever Fox – One Click Website Importer plugin for WordPress through version 25.2.0 lacks proper permission validation in the 'clever-fox-activate-theme' function, enabling authenticated users with subscriber privileges or higher to change the active theme without authorization. An attacker exploiting this flaw could set the theme to an invalid value, potentially rendering the website inaccessible.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.