The Brilliance <= 1.2.7, Activello <= 1.4.0, and Newspaper X <= 1.3.1 themes for WordPress are vulnerable to Plugin Activation/Deactivation. This is due to the 'activello_activate_plugin' and 'activello_deactivate_plugin' functions in the 'inc/welcome-screen/class-activello-welcome.php' file missing capability and security checks/nonces. This makes it possible for unauthenticated attackers to activate and deactivate arbitrary plugins installed on a vulnerable site.

Project Subscriptions

Vendors Products
Colorlib Subscribe
Activello Subscribe
Bonkers Subscribe
Newspaper X Subscribe
Pixova Lite Subscribe
Shapely Subscribe
Cpothemes Subscribe
Affluent Subscribe
Allegiant Subscribe
Brilliance Subscribe
Transcend Subscribe
Machothemes Subscribe
Antreas Subscribe
Medzone Lite Subscribe
Naturemag Lite Subscribe
Newsmag Subscribe
Regina Lite Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2020-24163 The Brilliance <= 1.2.7, Activello <= 1.4.0, and Newspaper X <= 1.3.1 themes for WordPress are vulnerable to Plugin Activation/Deactivation. This is due to the 'activello_activate_plugin' and 'activello_deactivate_plugin' functions in the 'inc/welcome-screen/class-activello-welcome.php' file missing capability and security checks/nonces. This makes it possible for unauthenticated attackers to activate and deactivate arbitrary plugins installed on a vulnerable site.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sat, 28 Dec 2024 01:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2024-12-28T00:54:23.163Z

Reserved: 2023-06-06T13:07:21.267Z

Link: CVE-2020-36721

cve-icon Vulnrichment

Updated: 2024-08-04T17:37:06.599Z

cve-icon NVD

Status : Modified

Published: 2023-06-07T02:15:12.297

Modified: 2024-11-21T05:30:09.553

Link: CVE-2020-36721

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses