diff --git a/data/theme_vulns.xml b/data/theme_vulns.xml
index 16feb4c9..12ca9d64 100644
--- a/data/theme_vulns.xml
+++ b/data/theme_vulns.xml
@@ -1535,12 +1535,64 @@
RCE
- Multiple vulnerabilities in Flash News theme for WordPress
+ Flash News - thumb.php src Parameter XSS
+ 89887
+ http://packetstormsecurity.com/files/120037/
http://seclists.org/fulldisclosure/2013/Feb/8
http://cxsecurity.com/issue/WLB-2013020010
- MULTI
+ XSS
+
+
+ Flash News - Multiple Script Path Disclosure
+
+ 89888
+ http://packetstormsecurity.com/files/120037/
+ http://seclists.org/fulldisclosure/2013/Feb/8
+ http://cxsecurity.com/issue/WLB-2013020010
+
+ FPD
+
+
+ Flash News - includes/test.php a Parameter XSS
+
+ 89889
+ http://packetstormsecurity.com/files/120037/
+ http://seclists.org/fulldisclosure/2013/Feb/8
+ http://cxsecurity.com/issue/WLB-2013020010
+
+ XSS
+
+
+ Flash News - includes/test.php Direct Request Information Disclosure
+
+ 89890
+ http://packetstormsecurity.com/files/120037/
+ http://seclists.org/fulldisclosure/2013/Feb/8
+ http://cxsecurity.com/issue/WLB-2013020010
+
+ UNKNOWN
+
+
+ Flash News - thumb.php src Parameter File Upload Arbitrary Code Execution
+
+ 89891
+ http://packetstormsecurity.com/files/120037/
+ http://seclists.org/fulldisclosure/2013/Feb/8
+ http://cxsecurity.com/issue/WLB-2013020010
+
+ UNKNOWN
+
+
+ Flash News - thumb.php src Parameter Remote DoS
+
+ 89892
+ http://packetstormsecurity.com/files/120037/
+ http://seclists.org/fulldisclosure/2013/Feb/8
+ http://cxsecurity.com/issue/WLB-2013020010
+
+ UNKNOWN