Description
Cross-Site Request Forgery (CSRF) vulnerability in themearile NewsExo newsexo allows Cross Site Request Forgery.This issue affects NewsExo: from n/a through <= 7.1.
Published: 2026-04-08
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation via CSRF
Action: Immediate Patch
AI Analysis

Impact

The NewsExo WordPress theme contains a CSRF vulnerability that allows an attacker to craft a request that a legitimate user will inadvertently submit. This can lead to unauthorized changes within the site, such as modifying settings, posting content, or performing actions that the user has permission for. The weakness is a missing or improperly validated anti‑CSRF token, represented by CWE‑352.

Affected Systems

Vulnerable versions are all NewsExo releases up to and including 7.1. Sites running any of these versions are at risk. The vulnerability does not affect newer releases beyond 7.1, so upgrading past this point removes the risk. The issue is present in the default installation of the theme, not requiring additional configuration.

Risk and Exploitability

The severity is considered high due to the potential for an attacker to cause arbitrary actions on behalf of an authenticated user. The EPSS score is not available, and the vulnerability is not currently listed in the CISA KEV catalog. The likely attack vector involves a malicious link or embedded form that the target user clicks or submits, sending a forged request to the site. Because the flaw does not require local execution or privileged access, it can be exploited remotely with minimal effort once a user visits the malicious page.

Generated by OpenCVE AI on April 8, 2026 at 09:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the NewsExo theme to the latest version (≥7.2).
  • Back up the site before performing the update.
  • Remove or replace the vulnerable theme if it is no longer needed.
  • Verify that the new version includes proper CSRF protection and that nonces or other anti‑CSRF mechanisms are active.

Generated by OpenCVE AI on April 8, 2026 at 09:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 08 Apr 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Themearile
Themearile newsexo
Wordpress
Wordpress wordpress
Vendors & Products Themearile
Themearile newsexo
Wordpress
Wordpress wordpress

Wed, 08 Apr 2026 08:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in themearile NewsExo newsexo allows Cross Site Request Forgery.This issue affects NewsExo: from n/a through <= 7.1.
Title WordPress NewsExo theme <= 7.1 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References

Subscriptions

Themearile Newsexo
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-08T08:30:25.559Z

Reserved: 2026-04-07T10:57:27.974Z

Link: CVE-2026-39618

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-04-08T09:16:31.730

Modified: 2026-04-08T21:26:35.910

Link: CVE-2026-39618

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-08T19:41:58Z

Weaknesses