Newspaper
Vendor:
First CVE: Sep 16, 2019 · Active for 6 years
6
Total CVEs
More Total CVEs than 80% of tracked products
1.5
Avg CVEs / Year
Higher CVE frequency than 56% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 43% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Newspaper over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 16, 2019
6 years ago
Most Recent CVE
Jun 15, 2024
771 days ago
CVE Severity & Scoring
Newspaper6 CVEs
67%
33%
All CVEs352,719 CVEs
45%
40%
11%
MediumCritical
Attack Vector
Local0 (0.0%)
Network6 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None2 (33.3%)
Unknown0 (0.0%)
Required4 (66.7%)
Privileges Required
Low0 (0.0%)
High1 (16.7%)
None5 (83.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-10972CRITICAL The newspaper theme before 6.7.2 for WordPress has a lack of options access control via td_ajax_update_panel. | Sep 16, 2019 | 9.8 | 43 | NO | YES |
CVE-2022-2627MEDIUM The Newspaper WordPress theme before 12 does not sanitise a parameter before outputting it back in an HTML attribute via an AJAX action, leading to a Reflected Cross-Site Scripting | Oct 31, 2022 | 6.1 | 32 | NO | YES |
CVE-2017-18634CRITICAL The newspaper theme before 6.7.2 for WordPress has script injection via td_ads[header] to admin-ajax.php. | Sep 16, 2019 | 9.8 | 28 | NO | NO |
CVE-2021-3135MEDIUM An issue was discovered in the tagDiv Newspaper theme 10.3.9.1 for WordPress. It allows XSS via the wp-admin/admin-ajax.php td_block_id parameter in a td_ajax_block API call. | Jul 19, 2021 | 6.1 | 23 | NO | NO |
CVE-2022-2167MEDIUM The Newspaper WordPress theme before 12 does not sanitise a parameter before outputting it back in an HTML attribute via an AJAX action, leading to a Reflected Cross-Site Scripting | Oct 31, 2022 | 6.1 | 21 | NO | NO |
CVE-2024-3815MEDIUM The Newspaper theme for WordPress is vulnerable to Stored Cross-Site Scripting via attachment meta in the archive page in all versions up to, and including, 12.6.5 due to insuffici | Jun 15, 2024 | 4.8 | 15 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (6 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
33.3% of CVEs· 98th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (6 CVEs).
Media Mentions
Signals from CVEs in this product scope (6 CVEs).
Top CNAs Publishing CVEs For Newspaper
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 10.3.9.1 | 1 | 6.1 | 0.8% | 0 | 0 |