cbcvebase.

Spicethemes Newsblogger vulnerabilities

3 known vulnerabilities affecting spicethemes/newsblogger.

Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3

Vulnerabilities

Page 1 of 1
CVE-2025-1304P2HIGHCVSS 8.8fixed in 0.2.5.2≤ 0.2.5.12025-05-01
CVE-2025-1304 [HIGH] CWE-862 CVE-2025-1304: The NewsBlogger theme for WordPress is vulnerable to arbitrary file uploads due to a missing capabil The NewsBlogger theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the newsblogger_install_and_activate_plugin() function in all versions up to, and including, 0.2.5.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload arbitrary files on the affected site's
nvd
CVE-2025-12821P3HIGHCVSS 8.8≥ 0.2.5.6, ≤ 0.2.6.12026-02-19
CVE-2025-12821 [HIGH] CWE-352 CVE-2025-12821: The NewsBlogger theme for WordPress is vulnerable to Cross-Site Request Forgery in versions 0.2.5.6 The NewsBlogger theme for WordPress is vulnerable to Cross-Site Request Forgery in versions 0.2.5.6 to 0.2.6.1. This is due to missing or incorrect nonce validation on the newsblogger_install_and_activate_plugin() function. This makes it possible for unauthenticated attackers to upload arbitrary files and achieve remote code execution via a forged requ
nvd
CVE-2025-1305P3HIGHCVSS 8.8fixed in 0.2.5.5≤ 0.2.5.42025-05-01
CVE-2025-1305 [HIGH] CWE-352 CVE-2025-1305: The NewsBlogger theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t The NewsBlogger theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.2.5.4. This is due to missing or incorrect nonce validation on the newsblogger_install_and_activate_plugin() function. This makes it possible for unauthenticated attackers to upload arbitrary files and achieve remote code execution via
nvd
Spicethemes Newsblogger vulnerabilities | cvebase