CVE-2024-1587: Blazethemes Newsmatic
Medium severity, CVSS 5.3. EPSS: 0.6% chance of exploitation in the next 30 days.
The Newsmatic theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.0 via the 'newsmatic_filter_posts_load_tab_content'. This makes it possible for unauthenticated attackers to view draft posts and post content.
Affected products
- Blazethemes Newsmatic: before 1.3.5 (fixed in 1.3.5)
Published 2024-04-09. Last modified 2026-06-17.