Cross-Site Request Forgery Vulnerability in NewsBlogger Theme for WordPress
CVE-2025-1305
8.8HIGH
What is CVE-2025-1305?
The NewsBlogger theme for WordPress is susceptible to Cross-Site Request Forgery (CSRF), allowing unauthenticated attackers to exploit vulnerabilities in the newsblogger_install_and_activate_plugin() function due to inadequate nonce validation. This flaw enables attackers to trick administrators into executing unauthorized actions, including uploading arbitrary files which can lead to remote code execution.
Affected Version(s)
NewsBlogger * <= 0.2.5.4