Clariti

Clariti has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 5.4, and the most serious one scores 5.4 out of 10.

The most common weakness is Missing Authorization, behind 1 of the records (100%).

The one issue recorded for Clariti has a vendor fix available, so running the current release closes it.

All of these findings were reported by Nabil Irawan. Clariti is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.

Strategic Overview

Avg CVSSMedium
5.4/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Clariti vulnerabilities before they are exploited.

Highest severity on recordCVSS 5.4CVE-2025-57991

Clariti <= 1.2.1 - Missing Authorization

Read the full analysis

Vulnerability Records

1 records
Showing 1–1 of 1 reports
Clariti banner
Latestv1.2.2
0.0(0)
0/100
Last Updated
2026-01-15 (8mo ago)
Active Installs
1,000+
Downloads
36,809
Requires WP
6.0+
Requires PHP
7.4+
Tested up to
WP 6.9.7
Created
2021-03-10 (6y ago)

The Clariti plugin allows you to easily sync your content to Clariti. Clariti uses the WordPress REST API to gather valuable insights about your site to help you optimize and organize your content. This plugin enables Clariti to sync your content in realtime. A Clariti account is required to use this plugin. You cannot use Clariti with this plugin alone. To learn more about Clariti, head to clariti.com. You should download this plugin if you have an active Clariti account and you want to be able to sync your WordPress site changes in realtime with Clariti. Optimize & Organize Your Content Clariti saves you loads of time. It’s a solid replacement for the spreadsheet tracker you’ve been using. Clariti allows you to sync your content data so that you can plan, organize, and optimize your content. Seamless Syncing The Clariti Plugin does not alter any of your data. This plugin allows Clariti to sync all new and updated posts in near realtime.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C