Spicethemes develops a focused set of WordPress themes and plugins for content publishing and site management, a category where web-facing input handling and administrative access control are foundational concerns. Vulnerabilities affecting the vendor skew toward serious outcomes and recur through weakness classes including cross-site request forgery, cross-site scripting, and missing authorization—flaws typical of template-driven WordPress extensions where form handling and permission boundaries are critical. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Spicethemes over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-1307CRITICAL The Newscrunch theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check in the newscrunch_install_and_activate_plugin() function in all version | Mar 4, 2025 | 9.8 | 29 | NO | NO |
CVE-2025-1304HIGH The NewsBlogger theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the newsblogger_install_and_activate_plugin() function in all versi | May 1, 2025 | 8.8 | 26 | NO | NO |
CVE-2025-1305HIGH The NewsBlogger theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.2.5.4. This is due to missing or incorrect nonce validation | May 1, 2025 | 8.8 | 25 | NO | NO |
CVE-2025-1306HIGH The Newscrunch theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8.4. This is due to missing or incorrect nonce validation on | Mar 4, 2025 | 8.8 | 25 | NO | NO |
CVE-2024-44003MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in spicethemes Spice Starter Sites spice-starter-sites allows Reflected XSS.This | Sep 18, 2024 | 6.1 | 18 | NO | NO |
CVE-2023-5362MEDIUM The Carousel, Recent Post Slider and Banner Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'spice_post_slider' shortcode in versions up to, and includ | Oct 30, 2023 | 5.4 | 18 | NO | NO |
CVE-2024-8430MEDIUM The Spice Starter Sites plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the spice_starter_sites_importer_creater functi | Oct 1, 2024 | 5.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Spicethemes.
Media articles that mention a CVE ID that affects a product developed by Spicethemes — matched by CVE ID, not by vendor name.