See how jnews compares to other vendors in security performance
The JNews - WordPress Newspaper Magazine Blog AMP Theme theme for WordPress is vulnerable to unauthorized user registration in all versions up to, and including, 11.6.6. This is due to the plugin not properly validate if the user can register option is enabled prior to creating a user though the registerhandler() function. This makes it possible for unauthenticated attackers to register as a user even when user registration is disabled.
The JNews WordPress theme before 8.0.6 did not sanitise the catid parameter in the POST request /?ajax-request=jnews (with action=jnewsbuildmegacategory), leading to a Reflected Cross-Site Scripting (XSS) issue.