Nemesis All-in-One | Newspaper Builder Elementor Extention
Nemesis All-in-One | Newspaper Builder Elementor Extention has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Nemesis All-in-One | Newspaper Builder Elementor Extention has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by Gab. Nemesis All-in-One | Newspaper Builder Elementor Extention is installed on roughly 10 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2025-31849Nemesis All-in-One <= 1.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Nemesis All-in-One | Newspaper Builder Elementor Extention
Author
fbtemplates
Nemesis All-in-One improves user experience and gives them a chance to create their content with an All in One posts block widget for Elementor. Instead of using an add-on with many widgets, you only have one that allows you to create many different designs as long as you have imagination. Leave everything else to us. If you are still not satisfied with this add-on, take a look at our Nemesis – News & Magazine WordPress Theme at Themeforest. There are many many other widgets as Sliders, Load More Posts etc… UPDATING Automatic updates should work like a charm; as always though, ensure you backup your site just in case. GET A COMPLETE WEBSITE IN JUST 3 STEPS Install and activate Nemesis All in One plugin Add a new Page with Elementor Page Builder Start to create newspaper content.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C