CVE-2020-36721
07.06.2023, 02:15
The Brilliance <= 1.2.7, Activello <= 1.4.0, and Newspaper X <= 1.3.1 themes for WordPress are vulnerable to Plugin Activation/Deactivation. This is due to the 'activello_activate_plugin' and 'activello_deactivate_plugin' functions in the 'inc/welcome-screen/class-activello-welcome.php' file missing capability and security checks/nonces. This makes it possible for unauthenticated attackers to activate and deactivate arbitrary plugins installed on a vulnerable site.Enginsight
Vendor | Product | Version |
---|---|---|
colorlib | activello | 𝑥 < 1.4.2 |
colorlib | bonkers | 𝑥 < 1.0.6 |
colorlib | illdy | 𝑥 < 2.1.7 |
colorlib | newspaper_x | 𝑥 < 1.3.2 |
colorlib | pixova_lite | 𝑥 < 2.0.7 |
colorlib | shapely | 𝑥 < 1.2.9 |
cpothemes | affluent | 𝑥 < 1.1.2 |
cpothemes | allegiant | 𝑥 < 1.2.6 |
cpothemes | brilliance | 𝑥 < 1.3.0 |
cpothemes | transcend | 𝑥 < 1.2.0 |
machothemes | antreas | 𝑥 < 1.0.7 |
machothemes | medzone_lite | 𝑥 < 1.2.6 |
machothemes | naturemag_lite | 𝑥 ≤ 1.0.4 |
machothemes | newsmag | 𝑥 < 2.4.2 |
machothemes | regina_lite | 𝑥 < 2.0.6 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References