All 3 CVE vulnerabilities found in NewsMash, with AI-generated Chinese analysis, references, and POCs.
Vendor: desertthemes
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2024-56208 | WordPress NewsMash theme <= 1.0.71 - Cross Site Scripting (XSS) vulnerability CWE-79 | 5.4AI | MediumAI | 2026-02-20 |
| CVE-2024-37441 | WordPress NewsMash theme <= 1.0.34 - Cross Site Request Forgery (CSRF) vulnerability CWE-352 | 4.3 | Medium | 2025-01-02 |
| CVE-2024-10849 | NewsMash <= 1.0.71 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 | 6.4 | Medium | 2024-12-06 |
All 3 known CVE vulnerabilities affecting NewsMash with full Chinese analysis, references, and POCs where available.