CVE-2025-1306

HIGH

Newscrunch <= 1.8.4 - Cross-Site Request Forgery via newscrunch_install_and_activate_plugin()

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2025-1306. PoCs published by Nxploited, Boshe99.

AI-analyzed exploit summary This PoC demonstrates a CSRF to arbitrary file upload vulnerability (CVE-2025-1306) in the Newscrunch WordPress theme, allowing unauthenticated attackers to achieve RCE by tricking an admin into uploading a malicious ZIP file.

Description

The Newscrunch theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8.4. This is due to missing or incorrect nonce validation on the newscrunch_install_and_activate_plugin() function. This makes it possible for unauthenticated attackers to upload arbitrary files via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Exploits (2)

nomisec WORKING POC 4 stars
by Nxploited · poc
https://github.com/Nxploited/CVE-2025-1306

This PoC demonstrates a CSRF to arbitrary file upload vulnerability (CVE-2025-1306) in the Newscrunch WordPress theme, allowing unauthenticated attackers to achieve RCE by tricking an admin into uploading a malicious ZIP file.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Newscrunch WordPress Theme (<= 1.8.4)
No auth needed
Prerequisites: Target running vulnerable Newscrunch theme · Admin user must visit malicious link
devstral-2 · analyzed Feb 16, 2026 Full analysis →
github WORKING POC
by Boshe99 · pythonpoc
https://github.com/Boshe99/CVE-Exploits/tree/main/CVE-2025-1306

The repository contains functional exploit code for CVE-2025-1306, targeting an arbitrary file upload vulnerability in the WordPress Plugin 3DPrint Lite 1.9.1.4. The exploit demonstrates the ability to upload a malicious file to a vulnerable WordPress site.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: WordPress Plugin 3DPrint Lite 1.9.1.4
No auth needed
Prerequisites: Vulnerable WordPress site with 3DPrint Lite plugin installed · Network access to the target
devstral-2 · analyzed Feb 27, 2026 Full analysis →

Scores

CVSS v3 8.8
EPSS 0.0046
EPSS Percentile 36.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-352
Status published
Products (2)
spicethemes/Newscrunch < 1.8.4
spicethemes/newscrunch < 1.8.4.1
Published Mar 04, 2025
Tracked Since Feb 18, 2026