Unauthorized Plugin Installation in Newsup Theme for WordPress
CVE-2025-8682
4.3MEDIUM
What is CVE-2025-8682?
The Newsup theme for WordPress contains a vulnerability that allows unauthorized users to install plugins without proper checks. Specifically, the flaw resides within the newsup_admin_info_install_plugin() function, which fails to implement necessary capability checks. This deficiency enables unauthenticated attackers to exploit the vulnerability and install the ansar-import plugin. Websites utilizing the Newsup theme are at risk, particularly those running versions up to and including 5.0.10. It is crucial for administrators to update their themes and review their plugin installations to mitigate the risk associated with this vulnerability.
Affected Version(s)
Newsup * <= 5.0.10