← Back to browse · API

CVE-2025-1307

Severity
CRITICAL
CVSS
9.8
EPSS
0.02122
Risk score
39.94
CISA KEV
No
PoC
No
Published
2025-03-04
Modified
2026-04-08
First seen
2026-08-07
Aliases
EUVD-2025-7386, GHSA-Q4HV-4JCG-PQG9
Products
spicethemes:Newscrunch 0 ≤1.8.4
Sources
euvd EUVD-2025-7386

Description

The Newscrunch theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check in the newscrunch_install_and_activate_plugin() function in all versions up to, and including, 1.8.4.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

References