CVE-2025-12821Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The NewsBlogger theme for WordPress is vulnerable to Cross-Site Request Forgery in versions 0.2.5.6 to 0.2.5.9. This is due to missing or incorrect nonce validation on the newsblogger_install_and_activate_plugin() function. This makes it possible for unauthenticated attackers to upload arbitrary files and achieve remote code execution via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. This is due to a reverted fix of CVE-2025-1305.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-352

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-19: 1Technical Details · 2026-02-19: 102-19
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • CVETodo@CveTodo
    Disclosure

    CVE-2025-12821 pertains to a Cross-Site Request Forgery (CSRF) vulnerability in the **NewsBlogger** WordPress theme, specifically affecting versions **0.2.5.6 to 0.2.6.1**. The core issue stems from missing or improperly implemented nonce validation in the `newsblogger_install_and_activate_plugin()` function. #Cybersecurity #CVE #HighSeverity #SecurityAlert #RemoteCodeExecution #XSS https://cvetodo.com/cve/CVE-2025-12821

    Post summary

    The post announces a CSRF flaw (CVE‑2025‑12821) in the NewsBlogger WordPress theme due to missing nonce validation, with no mention of exploitation or patch availability.

    0000033
    20 followersView on X

Explore more