The following themes for WordPress are vulnerable to Function Injections in versions up to and including Shapely <= 1.2.7, NewsMag <= 2.4.1, Activello <= 1.4.0, Illdy <= 2.1.4, Allegiant <= 1.2.2, Newspaper X <= 1.3.1, Pixova Lite <= 2.0.5, Brilliance <= 1.2.7, MedZone Lite <= 1.2.4, Regina Lite <= 2.0.4, Transcend <= 1.1.8, Affluent <= 1.1.0, Bonkers <= 1.0.4, Antreas <= 1.0.2, Sparkling <= 2.4.8, and NatureMag Lite <= 1.0.4. This is due to epsilon_framework_ajax_action. This makes it possible for unauthenticated attackers to call functions and achieve remote code execution.

Project Subscriptions

Vendors Products
Colorlib Subscribe
Activello Subscribe
Bonkers Subscribe
Newspaper X Subscribe
Pixova Lite Subscribe
Shapely Subscribe
Sparklinkg Subscribe
Cpothemes Subscribe
Affluent Subscribe
Allegiant Subscribe
Brilliance Subscribe
Transcend Subscribe
Machothemes Subscribe
Antreas Subscribe
Medzone Lite Subscribe
Naturemag Lite Subscribe
Newsmag Subscribe
Regina Lite Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sat, 28 Dec 2024 01:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2024-12-28T00:56:18.718Z

Reserved: 2023-06-06T12:45:33.848Z

Link: CVE-2020-36708

cve-icon Vulnrichment

Updated: 2024-08-04T17:37:06.752Z

cve-icon NVD

Status : Modified

Published: 2023-06-07T02:15:11.503

Modified: 2024-11-21T05:30:07.483

Link: CVE-2020-36708

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses