CVE-2025-39373: WordPress JNews theme <= 12.0.5 - Broken Access Control vulnerability
Published May 19, 2025
·Updated
Missing Authorization vulnerability in jegtheme JNews jnews allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JNews: from n/a through <= 12.0.5.
Other sources
Missing Authorization vulnerability in jegtheme JNews.This issue affects JNews: from n/a through 11.6.5.
— NVD
Affected Software
1 affected component
Jegtheme JNews Theme<=11.6.16, <=11.6.5
Event History
May 19, 2025
CVE Published
via MITRE·04:42 PM
Data Sourced
via MITRE·04:42 PM
DescriptionWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-39373?
CVE-2025-39373 is classified as a missing authorization vulnerability in the JNews theme.
2
How do I fix CVE-2025-39373?
To fix CVE-2025-39373, update the JNews theme to version 11.6.6 or later.
3
What versions of JNews are affected by CVE-2025-39373?
CVE-2025-39373 affects JNews versions from n/a up to and including 11.6.5.
4
What types of attacks can result from CVE-2025-39373?
CVE-2025-39373 could allow unauthorized users to access restricted functionalities or data.
5
Who is the vendor for the affected software in CVE-2025-39373?
The vendor for the affected software in CVE-2025-39373 is jegtheme.