CVE-2020-36708: Colorlib Activello

Critical severity, CVSS 9.8. EPSS: 65.3% chance of exploitation in the next 30 days.

The following themes for WordPress are vulnerable to Function Injections in versions up to and including Shapely <= 1.2.7, NewsMag <= 2.4.1, Activello <= 1.4.0, Illdy <= 2.1.4, Allegiant <= 1.2.2, Newspaper X <= 1.3.1, Pixova Lite <= 2.0.5, Brilliance <= 1.2.7, MedZone Lite <= 1.2.4, Regina Lite <= 2.0.4, Transcend <= 1.1.8, Affluent <= 1.1.0, Bonkers <= 1.0.4, Antreas <= 1.0.2, Sparkling <= 2.4.8, and NatureMag Lite <= 1.0.4. This is due to epsilon_framework_ajax_action. This makes it possible for unauthenticated attackers to call functions and achieve remote code execution.

Affected products

  • Colorlib Activello: before 1.4.2 (fixed in 1.4.2)
  • Colorlib Bonkers: before 1.0.6 (fixed in 1.0.6)
  • Colorlib Illdy: before 2.1.7 (fixed in 2.1.7)
  • Colorlib Newspaper X: before 1.3.2 (fixed in 1.3.2)
  • Colorlib Pixova Lite: before 2.0.7 (fixed in 2.0.7)
  • Colorlib Shapely: before 1.2.9 (fixed in 1.2.9)
  • Colorlib Sparklinkg: up to and including 2.4.8
  • Cpothemes Affluent: before 1.1.2 (fixed in 1.1.2)
  • Cpothemes Allegiant: before 1.2.6 (fixed in 1.2.6)
  • Cpothemes Brilliance: before 1.3.0 (fixed in 1.3.0)
  • Cpothemes Transcend: before 1.2.0 (fixed in 1.2.0)
  • Machothemes Antreas: before 1.0.7 (fixed in 1.0.7)
  • Machothemes Medzone Lite: before 1.2.6 (fixed in 1.2.6)
  • Machothemes Naturemag Lite: up to and including 1.0.4
  • Machothemes Newsmag: before 2.4.2 (fixed in 2.4.2)
  • Machothemes Regina Lite: before 2.0.6 (fixed in 2.0.6)

Published 2023-06-07. Last modified 2026-06-17.