theme

Jnews Vulnerabilities

3 known security issues reported for the Jnews WordPress theme. Most recent disclosed Apr 22, 2025.

3 medium

Running Jnews on your site? Check whether your installed version is affected.

Scan your site free

JNews <= 11.6.5 - Missing Authorization

medium

The JNews - WordPress Newspaper Magazine Blog AMP Theme theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 11.6.5. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 11.6.5
Fix:
No patched version reported
Disclosed:
Apr 22, 2025

CVE-2025-39373 on NVD →

JNews - WordPress Newspaper Magazine Blog AMP Theme <= 11.6.6 - Unauthorized User Registration

medium

The JNews - WordPress Newspaper Magazine Blog AMP Theme theme for WordPress is vulnerable to unauthorized user registration in all versions up to, and including, 11.6.6. This is due to the plugin not properly validate if the user can register option is enabled prior to creating a user though the register_handler() func...

CVSS:
5.3
Affected:
up to 11.6.6
Fixed in:
11.6.7
Disclosed:
Mar 4, 2025

CVE-2024-8682 on NVD →

JNews - WordPress Newspaper Magazine Blog AMP Theme < 8.0.6 - Reflected Cross-Site Scripting

medium

The JNews WordPress theme before 8.0.6 did not sanitise the cat_id parameter in the POST request /?ajax-request=jnews (with action=jnews_build_mega_category_*), leading to a Reflected Cross-Site Scripting (XSS) issue.

CVSS:
6.1
Affected:
up to 8.0.6
Fixed in:
8.0.6
Disclosed:
May 24, 2021

CVE-2021-24342 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database