216.73.216.133

CVE-2025-12821

· Published 19/02/2026 07:17 · Modified 19/02/2026 15:53

Labels: CVE-2025-12821 2026-02-19CVE-2025-12821CWE-352[email protected]

Essential information

Published
19/02/2026 07:17
Modified
19/02/2026 15:53
Author
Creator
CVSS
8.8 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVSS metrics

Description

The NewsBlogger theme for WordPress is vulnerable to Cross-Site Request Forgery in versions 0.2.5.6 to 0.2.6.1. This is due to missing or incorrect nonce validation on the newsblogger_install_and_activate_plugin() function. This makes it possible for unauthenticated attackers to upload arbitrary files and achieve remote code execution via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. This is due to a reverted fix of CVE-2025-1305.

NVD status

Status
Awaiting Analysis — CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
wordpress / newsblogger cpe:2.3:a:wordpress:newsblogger:0.2.5.6-0.2.6.1:*:*:*:*:wordpress:*:*

References