Junglewise Threat Intelligence

CVE-2026-81779: Silk Themes Newspapers X backdoor in uploaded files

CVE-2026-81779 · Severity: critical · CVSS 10 · Published 2026-08-31

Executive brief

Newspapers X is a WordPress theme used to build news and blog websites. A backdoor was intentionally embedded in the theme by the vendor's own account across three releases, allowing attackers to gain unauthorized administrative access, execute arbitrary code, and inject malware into affected sites. This is a complete compromise of site security and data.

Technical details

A backdoor vulnerability (classified as improper input validation but fundamentally a malicious code injection) exists in Newspapers X theme versions 1.0.46 through 1.0.48, where the vendor's account shipped a file called `more-functions.php` that was included in the theme. The vulnerability allows unauthenticated remote attackers to gain code execution and establish persistent administrative access via webshell files (e.g., `newspapers-x.php`) written to the uploads directory. The attack also deploys a rogue administrator account and activates a malicious auto-publisher plugin. No authentication or special preconditions are required; the backdoor is automatically present upon theme activation. The vulnerability is patched in version 1.0.49, which removes the malicious file and its include statement; however, sites already compromised must manually remove webshells, rogue accounts, and exfiltrated credentials.

Affected products

  • Silk Themes Newspapers X 1.0.46–1.0.48

Timeline

  • 2026-08-31: disclosed: CVE-2026-81779 published on NVD
  • 2026-08-31: patched: Fix available in version 1.0.49
  • 2026-08-26: other: Vulnerability reported by ashv4ni to Patchstack

References