id: CVE-2016-10972 info: name: Newspaper Theme 6.4–6.7.1 - Privilege Escalation author: pussycat0x severity: critical description: | Newspaper Theme versions 6.4 to 6.7.1 for WordPress lacked proper options access control through td_ajax_update_panel, which led to a Privilege Escalation vulnerability. impact: | Unauthenticated attackers can escalate their privileges to administrator level, allowing complete control over the WordPress site including content manipulation, user management, and potential site takeover. remediation: | Update to Newspaper Theme version 6.7.2 or later. reference: - https://wpscan.com/vulnerability/5365ecca-93e2-4bfc-bd4a-6f61d7d75e96/ classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H cvss-score: 9.8 cve-id: CVE-2016-10972 cwe-id: CWE-269 epss-score: 0.63051 epss-percentile: 0.98416 cpe: cpe:2.3:a:tagdiv:newspaper:*:*:*:*:*:wordpress:*:* metadata: fofa-query: 'body="wp-content/themes/mTheme-Unus/"' vendor: tagdiv product: newspaper framework: wordpress tags: wpscan,cve,cve2016,wp,wordpress,wpscan,wp-theme,newspaper,passive,vkev,vuln http: - method: GET path: - "{{BaseURL}}/wp-content/themes/Newspaper/style.css" matchers: - type: dsl dsl: - "status_code == 200" - "compare_versions(version, '>= 6.4', '<= 6.7.1')" - "contains(body, 'Newspaper')" condition: and extractors: - type: regex part: body group: 1 name: version regex: - 'Version: ([0-9.]+)' internal: true # digest: 4b0a00483046022100e1182924bd4cffbf4a42ff7832a32572d0f2130f74d9c71871262fcb8d36cbd0022100c8b200be7cd69f72f7e7aa9c1883b83074e4a267fe30756a8913b3a553323cd2:922c64590222798bb761d5b6d8e72950