JNews <= 11.6.5 - Missing Authorization
medium
The JNews - WordPress Newspaper Magazine Blog AMP Theme theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 11.6.5. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 11.6.5
- Fix:
- No patched version reported
- Disclosed:
- Apr 22, 2025
CVE-2025-39373 on NVD →
JNews - WordPress Newspaper Magazine Blog AMP Theme <= 11.6.6 - Unauthorized User Registration
medium
The JNews - WordPress Newspaper Magazine Blog AMP Theme theme for WordPress is vulnerable to unauthorized user registration in all versions up to, and including, 11.6.6. This is due to the plugin not properly validate if the user can register option is enabled prior to creating a user though the register_handler() func...
- CVSS:
- 5.3
- Affected:
- up to 11.6.6
- Fixed in:
- 11.6.7
- Disclosed:
- Mar 4, 2025
CVE-2024-8682 on NVD →
JNews - WordPress Newspaper Magazine Blog AMP Theme < 8.0.6 - Reflected Cross-Site Scripting
medium
The JNews WordPress theme before 8.0.6 did not sanitise the cat_id parameter in the POST request /?ajax-request=jnews (with action=jnews_build_mega_category_*), leading to a Reflected Cross-Site Scripting (XSS) issue.
- CVSS:
- 6.1
- Affected:
- up to 8.0.6
- Fixed in:
- 8.0.6
- Disclosed:
- May 24, 2021
CVE-2021-24342 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database