Unauthorized Plugin Installation in Newsup Theme for WordPress
CVE-2025-8682
What is CVE-2025-8682?
The Newsup theme for WordPress contains a vulnerability that allows unauthorized users to install plugins without proper checks. Specifically, the flaw resides within the newsup_admin_info_install_plugin() function, which fails to implement necessary capability checks. This deficiency enables unauthenticated attackers to exploit the vulnerability and install the ansar-import plugin. Websites utilizing the Newsup theme are at risk, particularly those running versions up to and including 5.0.10. It is crucial for administrators to update their themes and review their plugin installations to mitigate the risk associated with this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Newsup * <= 5.0.10
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved