NewsBlogger
NewsBlogger has 3 disclosed vulnerabilities in the WordSec catalog, reported between 2025 and 2026; 2 are fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 8.8, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 3 high. 2025 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 2 of the records (67%). Other recurring categories include Missing Authorization.
2 of the records (67%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2026.
3 independent researchers contributed these findings, one record each. NewsBlogger is installed on roughly 9,000 WordPress sites, so each unpatched flaw has a wide blast radius.
CVE-2025-12821NewsBlogger <= 0.2.5.6 - 0.2.6.1 - Cross-Site Request Forgery to Arbitrary Plugin Installation
Read the full analysisVulnerability Records

NewsBlogger
Author
spicethemes
newscrunchNewsBlogger is a dynamic and versatile child theme for the popular NewCrunch WordPress theme. Perfect for bloggers, journalists, and online magazines, it offers enhanced customization options, improved performance, and seamless integration with both the Gutenberg and Classic editors. Compatible to various popular plugins such as Elementor, Contact Form 7, Polylang and WPML. Theme is RTL ready and prioritizes user privacy and complies with the General Data Protection Regulation (GDPR) guidelines by refraining from collecting any personal data restricted under GDPR. The theme is also schema-ready, enhancing search engine visibility and optimization. To explore the theme further, feel free to check out our demo at: https://demo-news.spicethemes.com/startersite-1/. For video tutorial visit here https://www.youtube.com/playlist?list=PLTfjrb24Pq_DeJOZdKEaP3rZPbHuOCLtZ
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C