Newspaper
tagDiv · 6 CVEs
CVE-2024-3815
MEDIUM
Newspaper <= 12.6.5 - Authenticated (Author+) Stored Cross-Site Scripting via Attachment Meta
Jun 15, 2024
CVE-2022-3477
CRITICAL
tagDiv Composer < 3.5 - Unauthenticated Account Takeover
Nov 14, 2022
CVE-2022-2627
MEDIUM
Newspaper < 12 - Reflected Cross-Site Scripting
Oct 31, 2022
CVE-2022-2167
MEDIUM
Newspaper < 12 - Reflected Cross-Site Scripting
Oct 31, 2022
CVE-2021-3135
MEDIUM
An issue was discovered in the tagDiv Newspaper theme 10.3.9.1 for WordPress. It allows XSS via the wp-admin/admin-ajax…
Jul 19, 2021
CVE-2016-10972
CRITICAL
The newspaper theme before 6.7.2 for WordPress has a lack of options access control via td_ajax_update_panel.
Sep 16, 2019
CVE-2017-18634
CRITICAL
The newspaper theme before 6.7.2 for WordPress has script injection via td_ads[header] to admin-ajax.php.
Sep 16, 2019
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2024-3815 | Newspaper <= 12.6.5 - Authenticated (Author+) Stored Cross-Site Scripting via Attachment Meta | MEDIUM | 0.28% | Jun 15, 2024 |
| CVE-2022-3477 | tagDiv Composer < 3.5 - Unauthenticated Account Takeover | CRITICAL | 3.83% | Nov 14, 2022 |
| CVE-2022-2627 | Newspaper < 12 - Reflected Cross-Site Scripting | MEDIUM | 1.08% | Oct 31, 2022 |
| CVE-2022-2167 | Newspaper < 12 - Reflected Cross-Site Scripting | MEDIUM | 0.60% | Oct 31, 2022 |
| CVE-2021-3135 | An issue was discovered in the tagDiv Newspaper theme 10.3.9.1 for WordPress. It allows XSS via the wp-admin/admin-ajax.php td_block_id parameter in a td_ajax_… | MEDIUM | 0.83% | Jul 19, 2021 |
| CVE-2016-10972 | The newspaper theme before 6.7.2 for WordPress has a lack of options access control via td_ajax_update_panel. | CRITICAL | 9.27% | Sep 16, 2019 |
| CVE-2017-18634 | The newspaper theme before 6.7.2 for WordPress has script injection via td_ads[header] to admin-ajax.php. | CRITICAL | 2.17% | Sep 16, 2019 |
Showing 1 to 6 of 6 CVEs