theme

Newspaper Vulnerabilities

24 known security issues reported for the Newspaper WordPress theme. Most recent disclosed Jun 15, 2024.

3 critical 6 medium

Running Newspaper on your site? Check whether your installed version is affected.

Scan your site free

Newspaper - News & WooCommerce WordPress Theme [Newspaper] < 12.6.6

unknown

[en] The Newspaper theme for WordPress is vulnerable to Stored Cross-Site Scripting via attachment meta in the archive page in all versions up to, and including, 12.6.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with author...

Affected:
up to 12.6.6
Fixed in:
12.6.6
Disclosed:
Jun 15, 2024

CVE-2024-3815 on NVD →

Newspaper <= 12.6.5 - Authenticated (Author+) Stored Cross-Site Scripting via Attachment Meta

medium

The Newspaper theme for WordPress is vulnerable to Stored Cross-Site Scripting via attachment meta in the archive page in all versions up to, and including, 12.6.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with author-leve...

CVSS:
5.5
Affected:
up to 12.6.5
Fixed in:
12.6.6
Disclosed:
Apr 18, 2024

CVE-2024-3815 on NVD →

tagDiv Cloud Library < 2.7 - Missing Authorization to Arbitrary User Metadata Update

critical

The tagDiv Cloud Library plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tdb_user_form_on_submit() function called via an AJAX action in versions prior to 2.7. This makes it possible for unauthenticated attackers to modify arbitrary user metadata and gain...

CVSS:
9.8
Affected:
up to 12.3
Fixed in:
12.4
Disclosed:
Jun 19, 2023

CVE-2023-1597 on NVD →

Newspaper - News & WooCommerce WordPress Theme [Newspaper] < 12.1

unknown

[en] The tagDiv Composer WordPress plugin before 3.5, required by the Newspaper WordPress theme before 12.1 and Newsmag WordPress theme before 5.2.2, does not properly implement the Facebook login feature, allowing unauthenticated attackers to login as any user by just knowing their email address

Affected:
up to 12.1
Fixed in:
12.1
Disclosed:
Nov 14, 2022

CVE-2022-3477 on NVD →

Newspaper - News & WooCommerce WordPress Theme [Newspaper] < 12.0

unknown

[en] The Newspaper WordPress theme before 12 does not sanitise a parameter before outputting it back in an HTML attribute via an AJAX action, leading to a Reflected Cross-Site Scripting.

Affected:
up to 12.0
Fixed in:
12.0
Disclosed:
Oct 31, 2022

CVE-2022-2627 on NVD →

Newspaper - News & WooCommerce WordPress Theme [Newspaper] < 12.0

unknown

[en] The Newspaper WordPress theme before 12 does not sanitise a parameter before outputting it back in an HTML attribute via an AJAX action, leading to a Reflected Cross-Site Scripting

Affected:
up to 12.0
Fixed in:
12.0
Disclosed:
Oct 31, 2022

CVE-2022-2167 on NVD →

tagDiv Composer < 3.5 - Unauthorized Account Access and Privilege Escalation

critical

The tagDiv Composer plugin for WordPress is vulnerable to Unauthorized Account Access and Privilege Escalation in versions up to, but not including, 3.5 due to improper implementation of the Facebook login feature. This allows unauthenticated attackers to log in as any user as long as they know the user's email addres...

CVSS:
9.8
Affected:
up to 12
Fixed in:
12.1
Disclosed:
Oct 24, 2022

CVE-2022-3477 on NVD →

Newspaper <= 11.5.1 - Reflected Cross-Site Scripting

medium

The Newspaper theme for WordPress is vulnerable to Reflected Cross-Site Scripting via an AJAX action in versions up to, and including, 11.5.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can...

CVSS:
6.1
Affected:
up to 11.5.1
Fixed in:
12
Disclosed:
Oct 10, 2022

CVE-2022-2167 on NVD →

Newspaper <= 11.5.1 - Reflected Cross-Site Scripting

medium

The Newspaper theme for WordPress is vulnerable to Reflected Cross-Site Scripting via an AJAX action in versions up to, and including, 11.5.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can...

CVSS:
6.1
Affected:
up to 11.5.1
Fixed in:
12
Disclosed:
Oct 10, 2022

CVE-2022-2627 on NVD →

Newspaper - News & WooCommerce WordPress Theme [Newspaper] < 11.0

unknown

[en] An issue was discovered in the tagDiv Newspaper theme 10.3.9.1 for WordPress. It allows XSS via the wp-admin/admin-ajax.php td_block_id parameter in a td_ajax_block API call.

Affected:
up to 11.0
Fixed in:
11.0
Disclosed:
Jul 19, 2021

CVE-2021-3135 on NVD →

Newspaper - News & WooCommerce WordPress Theme [Newspaper] < 11.0

unknown

Reflected Cross-Site Scripting (XSS) vulnerability discovered by Truoc Phan in WordPress Newspaper premium theme (versions <= 10.4).

Affected:
up to 11.0
Fixed in:
11.0
Disclosed:
Jun 30, 2021

Newspaper <= 10.3.3 - Reflected Cross-Site Scripting

medium

The Newspaper plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 10.3.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully tric...

CVSS:
6.1
Affected:
up to 10.3.3
Fixed in:
10.3.4
Disclosed:
Jun 3, 2020

Newspaper - News & WooCommerce WordPress Theme [Newspaper] < 10.3.4

unknown

Authenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered by Julio Potier (Secupress) in WordPress Newspaper premium theme (versions <= 10.3.3).

Affected:
up to 10.3.4
Fixed in:
10.3.4
Disclosed:
Jun 3, 2020

Newspaper - News & WooCommerce WordPress Theme [Newspaper] < 10.3.4

unknown

The Newspaper plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 10.3.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully tric...

Affected:
up to 10.3.4
Fixed in:
10.3.4
Disclosed:
Jun 3, 2020

Newspaper - News & WooCommerce WordPress Theme [Newspaper] < 6.7.2

unknown

[en] The newspaper theme before 6.7.2 for WordPress has script injection via td_ads[header] to admin-ajax.php.

Affected:
up to 6.7.2
Fixed in:
6.7.2
Disclosed:
Sep 16, 2019

CVE-2017-18634 on NVD →

Newspaper - News & WooCommerce WordPress Theme [Newspaper] < 6.7.2

unknown

[en] The newspaper theme before 6.7.2 for WordPress has a lack of options access control via td_ajax_update_panel.

Affected:
up to 6.7.2
Fixed in:
6.7.2
Disclosed:
Sep 16, 2019

CVE-2016-10972 on NVD →

Newspaper < 9.2.2 - Cross-Site Scripting

medium

The Newspaper theme for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 9.2.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
6.1
Affected:
up to 9.2.2
Fixed in:
9.2.2
Disclosed:
Feb 14, 2019

Newspaper - News & WooCommerce WordPress Theme [Newspaper] < 9.5

unknown

Cross-Site Scripting (XSS) vulnerability found in WordPress Newspaper theme (versions <= 9.2.2).

Affected:
up to 9.5
Fixed in:
9.5
Disclosed:
Feb 14, 2019

Newspaper - News & WooCommerce WordPress Theme [Newspaper] < 9.2.2

unknown

The Newspaper theme for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 9.2.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

Affected:
up to 9.2.2
Fixed in:
9.2.2
Disclosed:
Feb 14, 2019

Newspaper - News & WooCommerce WordPress Theme <= 6.7 - Arbitrary Options Update

critical

The newspaper theme before 6.7.2 for WordPress has a lack of options access control via td_ajax_update_panel.

CVSS:
9.8
Affected:
up to 6.7.1
Fixed in:
6.7.2
Disclosed:
Jun 6, 2016

CVE-2016-10972 on NVD →

Newspaper - News & WooCommerce WordPress Theme < 6.7.2 - Cross-Site Scripting

medium

The newspaper theme before 6.7.2 for WordPress has script injection via td_ads[header] to admin-ajax.php.

CVSS:
6.5
Affected:
up to 6.7.2
Fixed in:
6.7.2
Disclosed:
Jun 6, 2016

CVE-2017-18634 on NVD →

Newspaper - News & WooCommerce WordPress Theme [Newspaper] < 6.7.2

unknown

This WordPress Newspaper theme is prone to a privilege escalation vulnerability. Update the plugin.

Affected:
up to 6.7.2
Fixed in:
6.7.2
Disclosed:
Jun 6, 2016

Newspaper - News & WooCommerce WordPress Theme [Newspaper] < 9.5

unknown

From the changelog: Newspaper - Version: 9.2.2 fix: XSS Security issue.

Affected:
up to 9.5
Fixed in:
9.5

Newspaper - News & WooCommerce WordPress Theme [Newspaper] < 10.3.4

unknown

Julio Potier, from Secupress, found an authenticated (admin+) reflected XSS in the Newspaper theme.

Affected:
up to 10.3.4
Fixed in:
10.3.4

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database