Newspaper - News & WooCommerce WordPress Theme [Newspaper] < 12.6.6
unknown
[en] The Newspaper theme for WordPress is vulnerable to Stored Cross-Site Scripting via attachment meta in the archive page in all versions up to, and including, 12.6.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with author...
- Affected:
- up to 12.6.6
- Fixed in:
- 12.6.6
- Disclosed:
- Jun 15, 2024
CVE-2024-3815 on NVD →
Newspaper <= 12.6.5 - Authenticated (Author+) Stored Cross-Site Scripting via Attachment Meta
medium
The Newspaper theme for WordPress is vulnerable to Stored Cross-Site Scripting via attachment meta in the archive page in all versions up to, and including, 12.6.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with author-leve...
- CVSS:
- 5.5
- Affected:
- up to 12.6.5
- Fixed in:
- 12.6.6
- Disclosed:
- Apr 18, 2024
CVE-2024-3815 on NVD →
tagDiv Cloud Library < 2.7 - Missing Authorization to Arbitrary User Metadata Update
critical
The tagDiv Cloud Library plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tdb_user_form_on_submit() function called via an AJAX action in versions prior to 2.7. This makes it possible for unauthenticated attackers to modify arbitrary user metadata and gain...
- CVSS:
- 9.8
- Affected:
- up to 12.3
- Fixed in:
- 12.4
- Disclosed:
- Jun 19, 2023
CVE-2023-1597 on NVD →
Newspaper - News & WooCommerce WordPress Theme [Newspaper] < 12.1
unknown
[en] The tagDiv Composer WordPress plugin before 3.5, required by the Newspaper WordPress theme before 12.1 and Newsmag WordPress theme before 5.2.2, does not properly implement the Facebook login feature, allowing unauthenticated attackers to login as any user by just knowing their email address
- Affected:
- up to 12.1
- Fixed in:
- 12.1
- Disclosed:
- Nov 14, 2022
CVE-2022-3477 on NVD →
Newspaper - News & WooCommerce WordPress Theme [Newspaper] < 12.0
unknown
[en] The Newspaper WordPress theme before 12 does not sanitise a parameter before outputting it back in an HTML attribute via an AJAX action, leading to a Reflected Cross-Site Scripting.
- Affected:
- up to 12.0
- Fixed in:
- 12.0
- Disclosed:
- Oct 31, 2022
CVE-2022-2627 on NVD →
Newspaper - News & WooCommerce WordPress Theme [Newspaper] < 12.0
unknown
[en] The Newspaper WordPress theme before 12 does not sanitise a parameter before outputting it back in an HTML attribute via an AJAX action, leading to a Reflected Cross-Site Scripting
- Affected:
- up to 12.0
- Fixed in:
- 12.0
- Disclosed:
- Oct 31, 2022
CVE-2022-2167 on NVD →
tagDiv Composer < 3.5 - Unauthorized Account Access and Privilege Escalation
critical
The tagDiv Composer plugin for WordPress is vulnerable to Unauthorized Account Access and Privilege Escalation in versions up to, but not including, 3.5 due to improper implementation of the Facebook login feature. This allows unauthenticated attackers to log in as any user as long as they know the user's email addres...
- CVSS:
- 9.8
- Affected:
- up to 12
- Fixed in:
- 12.1
- Disclosed:
- Oct 24, 2022
CVE-2022-3477 on NVD →
Newspaper <= 11.5.1 - Reflected Cross-Site Scripting
medium
The Newspaper theme for WordPress is vulnerable to Reflected Cross-Site Scripting via an AJAX action in versions up to, and including, 11.5.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can...
- CVSS:
- 6.1
- Affected:
- up to 11.5.1
- Fixed in:
- 12
- Disclosed:
- Oct 10, 2022
CVE-2022-2167 on NVD →
Newspaper <= 11.5.1 - Reflected Cross-Site Scripting
medium
The Newspaper theme for WordPress is vulnerable to Reflected Cross-Site Scripting via an AJAX action in versions up to, and including, 11.5.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can...
- CVSS:
- 6.1
- Affected:
- up to 11.5.1
- Fixed in:
- 12
- Disclosed:
- Oct 10, 2022
CVE-2022-2627 on NVD →
Newspaper - News & WooCommerce WordPress Theme [Newspaper] < 11.0
unknown
[en] An issue was discovered in the tagDiv Newspaper theme 10.3.9.1 for WordPress. It allows XSS via the wp-admin/admin-ajax.php td_block_id parameter in a td_ajax_block API call.
- Affected:
- up to 11.0
- Fixed in:
- 11.0
- Disclosed:
- Jul 19, 2021
CVE-2021-3135 on NVD →
Newspaper - News & WooCommerce WordPress Theme [Newspaper] < 11.0
unknown
Reflected Cross-Site Scripting (XSS) vulnerability discovered by Truoc Phan in WordPress Newspaper premium theme (versions <= 10.4).
- Affected:
- up to 11.0
- Fixed in:
- 11.0
- Disclosed:
- Jun 30, 2021
Newspaper <= 10.3.3 - Reflected Cross-Site Scripting
medium
The Newspaper plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 10.3.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully tric...
- CVSS:
- 6.1
- Affected:
- up to 10.3.3
- Fixed in:
- 10.3.4
- Disclosed:
- Jun 3, 2020
Newspaper - News & WooCommerce WordPress Theme [Newspaper] < 10.3.4
unknown
Authenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered by Julio Potier (Secupress) in WordPress Newspaper premium theme (versions <= 10.3.3).
- Affected:
- up to 10.3.4
- Fixed in:
- 10.3.4
- Disclosed:
- Jun 3, 2020
Newspaper - News & WooCommerce WordPress Theme [Newspaper] < 10.3.4
unknown
The Newspaper plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 10.3.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully tric...
- Affected:
- up to 10.3.4
- Fixed in:
- 10.3.4
- Disclosed:
- Jun 3, 2020
Newspaper - News & WooCommerce WordPress Theme [Newspaper] < 6.7.2
unknown
[en] The newspaper theme before 6.7.2 for WordPress has script injection via td_ads[header] to admin-ajax.php.
- Affected:
- up to 6.7.2
- Fixed in:
- 6.7.2
- Disclosed:
- Sep 16, 2019
CVE-2017-18634 on NVD →
Newspaper - News & WooCommerce WordPress Theme [Newspaper] < 6.7.2
unknown
[en] The newspaper theme before 6.7.2 for WordPress has a lack of options access control via td_ajax_update_panel.
- Affected:
- up to 6.7.2
- Fixed in:
- 6.7.2
- Disclosed:
- Sep 16, 2019
CVE-2016-10972 on NVD →
Newspaper < 9.2.2 - Cross-Site Scripting
medium
The Newspaper theme for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 9.2.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- CVSS:
- 6.1
- Affected:
- up to 9.2.2
- Fixed in:
- 9.2.2
- Disclosed:
- Feb 14, 2019
Newspaper - News & WooCommerce WordPress Theme [Newspaper] < 9.5
unknown
Cross-Site Scripting (XSS) vulnerability found in WordPress Newspaper theme (versions <= 9.2.2).
- Affected:
- up to 9.5
- Fixed in:
- 9.5
- Disclosed:
- Feb 14, 2019
Newspaper - News & WooCommerce WordPress Theme [Newspaper] < 9.2.2
unknown
The Newspaper theme for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 9.2.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- Affected:
- up to 9.2.2
- Fixed in:
- 9.2.2
- Disclosed:
- Feb 14, 2019
Newspaper - News & WooCommerce WordPress Theme <= 6.7 - Arbitrary Options Update
critical
The newspaper theme before 6.7.2 for WordPress has a lack of options access control via td_ajax_update_panel.
- CVSS:
- 9.8
- Affected:
- up to 6.7.1
- Fixed in:
- 6.7.2
- Disclosed:
- Jun 6, 2016
CVE-2016-10972 on NVD →
Newspaper - News & WooCommerce WordPress Theme < 6.7.2 - Cross-Site Scripting
medium
The newspaper theme before 6.7.2 for WordPress has script injection via td_ads[header] to admin-ajax.php.
- CVSS:
- 6.5
- Affected:
- up to 6.7.2
- Fixed in:
- 6.7.2
- Disclosed:
- Jun 6, 2016
CVE-2017-18634 on NVD →
Newspaper - News & WooCommerce WordPress Theme [Newspaper] < 6.7.2
unknown
This WordPress Newspaper theme is prone to a privilege escalation vulnerability.
Update the plugin.
- Affected:
- up to 6.7.2
- Fixed in:
- 6.7.2
- Disclosed:
- Jun 6, 2016
Newspaper - News & WooCommerce WordPress Theme [Newspaper] < 9.5
unknown
From the changelog:
Newspaper - Version: 9.2.2
fix: XSS Security issue.
- Affected:
- up to 9.5
- Fixed in:
- 9.5
Newspaper - News & WooCommerce WordPress Theme [Newspaper] < 10.3.4
unknown
Julio Potier, from Secupress, found an authenticated (admin+) reflected XSS in the Newspaper theme.
- Affected:
- up to 10.3.4
- Fixed in:
- 10.3.4
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database