VendorstagDivnewspaperany version
Vulnerabilities

tagDiv Newspaper any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2016-10972
The newspaper theme before 6.7.2 for WordPress has a lack of options access control via td_ajax_update_panel.
Published 2019-09-16 · Modified
9.8EPSS 0.093
CVE-2017-18634
The newspaper theme before 6.7.2 for WordPress has script injection via td_ads[header] to admin-ajax.php.
Published 2019-09-16 · Modified
9.8EPSS 0.022
CVE-2022-2627
Newspaper < 12 - Reflected Cross-Site Scripting
Published 2022-10-31 · Modified
6.1EPSS 0.010
CVE-2022-2167
Newspaper < 12 - Reflected Cross-Site Scripting
Published 2022-10-31 · Modified
6.1EPSS 0.006
CVE-2024-3815
Newspaper <= 12.6.5 - Authenticated (Author+) Stored Cross-Site Scripting via Attachment Meta
Published 2024-06-15 · Modified
5.5EPSS 0.003