CVE-2024-8682

JNews - WordPress Newspaper Magazine Blog AMP Theme <= 11.6.6 - Unauthorized User Registration

The JNews - WordPress Newspaper Magazine Blog AMP Theme theme for WordPress is vulnerable to unauthorized user registration in all versions up to, and including, 11.6.6. This is due to the plugin not properly validate if the user can register option is enabled prior to creating a user though the register_handler() function. This makes it possible for unauthenticated attackers to register as a user even when user registration is disabled.


We have discovered 4,852 live websites that are affected by CVE-2024-8682.

Run a Free Instant Scan




Affected Software

Product  JNews
Category Wordpress Themes
Vulnerable Domains4,852 live websites (68% of JNews install base)
Vulnerable Versions
  • from 0 through 11.6.6
Vulnerable Versions Count137 versions ( 85% of all versions)


Common Weakness Enumeration

CWE-862 Missing Authorization



Details

  • Published - Mar 5, 2025
  • Updated - Apr 8, 2026

Credits

  • Kubow (finder)

Website Distribution by Country

Number of websites using CVE-2024-8682
United States1,653 websites



Germany326 websites
Vietnam236 websites
Brazil224 websites
Indonesia198 websites
France177 websites
Cyprus176 websites
GB155 websites
Italy140 websites
India105 websites

Website Distribution by TLD

Number of websites using CVE-2024-8682
.com2,307 websites
.net208 websites
.org192 websites
.com.br190 websites
.it118 websites
.pl68 websites
.de66 websites
.ru58 websites
.nl53 websites
.info45 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-8682

Top websites that are affected by CVE-2024-8682. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***********.com United States**,***
******.**.id China**,***
******.**.th China**,***
******.vn China**,***
********.com United States**,***
**************.com United States**,***
**********.com United States**,***
************.***.br Brazil**,***
********.org **,***
**********.com United States**,***
See full domain list

FAQ

CVE-2024-8682 is Missing Authorization in JNews
A total of 4,852 websites have been identified as vulnerable to CVE-2024-8682, based on global website indexing conducted by WebTechSurvey.
The JNews is affected by the CVE-2024-8682 vulnerability.
JNews versions up to and including 11.6.6 are vulnerable to CVE-2024-8682.