CVE-2026-81779
—Unauthenticated malware implantation flaw in Silk Themes Newspapers X
Newspapers X, a WordPress theme by Silk Themes, contains an improper validation of a specified quantity in input (CWE-1284) in versions 1.0.46 through 1.0.48, which allows an attacker to implant malicious software on affected sites. Because the flaw is rated with network attack vector, no privileges required, and no user interaction, it can be triggered remotely by an unauthenticated attacker sending a crafted request that supplies an unvalidated quantity to the vulnerable component. The CVSS 3.1 score of 10.0 with scope changed and high confidentiality, integrity, and availability impact indicates the attacker can gain deep control of the site, including implanting malware and potentially affecting resources beyond the vulnerable component. Sites running Newspapers X versions 1.0.46 through 1.0.48 are affected; per the advisory, versions outside this range, including those before 1.0.46, are not listed as vulnerable. No public proof-of-concept is known, exploitation probability is low (EPSS 0.3%), and the flaw is not in CISA KEV, so no exploitation is currently known.
What to do: Update the Newspapers X theme to the latest available release beyond version 1.0.48 and confirm the running version in the WordPress admin (Appearance > Themes). If an immediate update is not possible, consider temporarily switching themes or deploying a WAF/virtual-patching rule that limits unvalidated quantity inputs, since the flaw is exploitable without authentication. Monitor theme vendor advisories for the fixed version number, as none is specified in the available data.
| Silk Themes Newspapers X (WordPress theme) | 1.0.46 through 1.0.48 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper Validation of Specified Quantity in Input vulnerability in Silk Themes Newspapers X allows Malicious Software Implanted. This issue affects Newspapers X: from 1.0.46 through 1.0.48.
- Ecosystems
- WordPress
- Weakness
- CWE-1284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.