8.8

CVE-2025-12821

NewsBlogger <= 0.2.5.6 - 0.2.5.9 - Cross-Site Request Forgery to Arbitrary Plugin Installation

NewsBlogger <= 0.2.5.6 - 0.2.5.9 - Cross-Site Request Forgery to Arbitrary Plugin Installation

The NewsBlogger theme for WordPress is vulnerable to Cross-Site Request Forgery in versions 0.2.5.6  to 0.2.5.9. This is due to missing or incorrect nonce validation on the newsblogger_install_and_activate_plugin() function. This makes it possible for unauthenticated attackers to upload arbitrary files and achieve remote code execution via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. This is due to a reverted fix of CVE-2025-1305.
Mögliche Gegenmaßnahme
NewsBlogger: Update to version 0.2.6, or a newer patched version
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellerspicethemes
≫
Produkt NewsBlogger
Default Statusunaffected
Version <= 0.2.5.9
Version 0.2.5.6
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Weitere Schwachstelleninformationen
SystemWordPress Theme
≫
Produkt NewsBlogger
Version 0.2.5.6-0.2.5.9
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.29% 0.201
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security@wordfence.com 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-352 Cross-Site Request Forgery (CSRF)

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

https://www.wordfence.com/threat-intel/vulnerabilities/id/9f33096a-dfd5-48c1-84d8-30a0faa2a7f5?source=cve
https://themes.trac.wordpress.org/browser/newsblogger/0.2.5.8/functions.php#L499
https://themes.trac.wordpress.org/changeset?old=302341&old_path=%2Fnewsblogger%2F0.2.5.9%2Ffunctions.php&new=304663&new_path=%2Fnewsblogger%2F0.2.6%2Ffunctions.php
https://www.wordfence.com/threat-intel/vulnerabilities/id/9f33096a-dfd5-48c1-84d8-30a0faa2a7f5
Third Party Advisory