8.8
CVE-2025-12821
- EPSS 0.29%
- Veröffentlicht 19.02.2026 03:25:16
- Zuletzt bearbeitet 14.09.2026 23:17:14
- Erkennungen
NewsBlogger <= 0.2.5.6 - 0.2.5.9 - Cross-Site Request Forgery to Arbitrary Plugin Installation
NewsBlogger <= 0.2.5.6 - 0.2.5.9 - Cross-Site Request Forgery to Arbitrary Plugin Installation
The NewsBlogger theme for WordPress is vulnerable to Cross-Site Request Forgery in versions 0.2.5.6 to 0.2.5.9. This is due to missing or incorrect nonce validation on the newsblogger_install_and_activate_plugin() function. This makes it possible for unauthenticated attackers to upload arbitrary files and achieve remote code execution via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. This is due to a reverted fix of CVE-2025-1305.
Mögliche Gegenmaßnahme
NewsBlogger: Update to version 0.2.6, or a newer patched version
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellerspicethemes
≫
Produkt
NewsBlogger
Default Statusunaffected
Version <=
0.2.5.9
Version
0.2.5.6
Status
affected
VulnDex Vulnerability Enrichment
Weitere Schwachstelleninformationen
SystemWordPress Theme
≫
Produkt
NewsBlogger
Version
0.2.5.6-0.2.5.9
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.29% | 0.201 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security@wordfence.com | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-352 Cross-Site Request Forgery (CSRF)
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
https://www.wordfence.com/threat-intel/vulnerabilities/id/9f33096a-dfd5-48c1-84d8-30a0faa2a7f5?source=cve
https://themes.trac.wordpress.org/browser/newsblogger/0.2.5.8/functions.php#L499
https://themes.trac.wordpress.org/changeset?old=302341&old_path=%2Fnewsblogger%2F0.2.5.9%2Ffunctions.php&new=304663&new_path=%2Fnewsblogger%2F0.2.6%2Ffunctions.php
https://www.wordfence.com/threat-intel/vulnerabilities/id/9f33096a-dfd5-48c1-84d8-30a0faa2a7f5