VYPR

News Theme

by WordPress

CVEs (2)

  • CVE-2021-24304MedAug 9, 2021
    risk 0.40cvss 6.1epss 0.01

    The Newsmag WordPress theme before 5.0 does not sanitise the td_block_id parameter in its td_ajax_block AJAX action, leading to an unauthenticated Reflected Cross-site Scripting (XSS) vulnerability.

  • CVE-2026-8167MedJul 28, 2026
    risk 0.00cvss 6.1epss 0.00

    Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in THEWP Digital Solutions News Theme V8 allows Reflected XSS. This issue affects News Theme V8: through 16.06.2026.