Impact
This vulnerability arises from inadequate validation of the quantity specified in user input, permitting an attacker to implant malicious software that can override normal theme behavior and potentially execute arbitrary code. The flaw effectively provides a backdoor mechanism for code injection, which threatens the confidentiality, integrity, and availability of the affected WordPress site.
Affected Systems
Silk Themes’ Newspapers X WordPress theme, versions 1.0.46 through 1.0.48, is affected. Any site deploying these versions is susceptible to exploitation.
Risk and Exploitability
The CVSS score of 10 indicates critical severity. The EPSS score is not available, so the likelihood of widespread exploitation is unclear. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that attackers may exploit the flaw via remote HTTP requests targeting the theme’s input endpoints; however, the CVE data does not specify whether authentication is required. Consequently, it is uncertain whether the backdoor can be triggered by unauthenticated users or only by users with privileged access.
OpenCVE Enrichment