Junglewise Threat Intelligence

CVE-2026-39618: themearile NewsExo CSRF in WordPress theme

CVE-2026-39618 · Severity: medium · CVSS 4.3 · Published 2026-04-08

Executive brief

The NewsExo theme for WordPress is vulnerable to an attack that can trick an administrator into performing unintended actions. By getting a logged-in user to click a malicious link, an attacker could potentially change site settings or perform other administrative tasks without the user's consent. This could lead to unauthorized modifications of the website's content or configuration.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the themearile NewsExo theme for WordPress through version 8.4. The vulnerability stems from a lack of proper nonce validation or similar request-signing mechanisms on sensitive administrative functions. An unauthenticated remote attacker can exploit this by crafting a malicious webpage or link and tricking a logged-in administrator into interacting with it. Successful exploitation allows the attacker to perform actions with the privileges of the victim user, such as modifying theme settings or site content. As of the latest advisory, no official patch has been released.

Affected products

  • themearile NewsExo <= 8.4

Timeline

  • 2026-01-12: other: Vulnerability reported by researcher
  • 2026-02-11: advisory: Patchstack published advisory
  • 2026-04-08: disclosed: CVE published to NVD

References