Unauthorized Plugin Installation in Newsup Theme for WordPress
CVE-2025-8682

4.3MEDIUM

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
11 October 2025

What is CVE-2025-8682?

The Newsup theme for WordPress contains a vulnerability that allows unauthorized users to install plugins without proper checks. Specifically, the flaw resides within the newsup_admin_info_install_plugin() function, which fails to implement necessary capability checks. This deficiency enables unauthenticated attackers to exploit the vulnerability and install the ansar-import plugin. Websites utilizing the Newsup theme are at risk, particularly those running versions up to and including 5.0.10. It is crucial for administrators to update their themes and review their plugin installations to mitigate the risk associated with this vulnerability.

Affected Version(s)

Newsup * <= 5.0.10

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dmitrii Ignatyev
.
CVE-2025-8682 : Unauthorized Plugin Installation in Newsup Theme for WordPress