CVE-2020-36708: Colorlib Activello
Critical severity, CVSS 9.8. EPSS: 65.3% chance of exploitation in the next 30 days.
The following themes for WordPress are vulnerable to Function Injections in versions up to and including Shapely <= 1.2.7, NewsMag <= 2.4.1, Activello <= 1.4.0, Illdy <= 2.1.4, Allegiant <= 1.2.2, Newspaper X <= 1.3.1, Pixova Lite <= 2.0.5, Brilliance <= 1.2.7, MedZone Lite <= 1.2.4, Regina Lite <= 2.0.4, Transcend <= 1.1.8, Affluent <= 1.1.0, Bonkers <= 1.0.4, Antreas <= 1.0.2, Sparkling <= 2.4.8, and NatureMag Lite <= 1.0.4. This is due to epsilon_framework_ajax_action. This makes it possible for unauthenticated attackers to call functions and achieve remote code execution.
Affected products
- Colorlib Activello: before 1.4.2 (fixed in 1.4.2)
- Colorlib Bonkers: before 1.0.6 (fixed in 1.0.6)
- Colorlib Illdy: before 2.1.7 (fixed in 2.1.7)
- Colorlib Newspaper X: before 1.3.2 (fixed in 1.3.2)
- Colorlib Pixova Lite: before 2.0.7 (fixed in 2.0.7)
- Colorlib Shapely: before 1.2.9 (fixed in 1.2.9)
- Colorlib Sparklinkg: up to and including 2.4.8
- Cpothemes Affluent: before 1.1.2 (fixed in 1.1.2)
- Cpothemes Allegiant: before 1.2.6 (fixed in 1.2.6)
- Cpothemes Brilliance: before 1.3.0 (fixed in 1.3.0)
- Cpothemes Transcend: before 1.2.0 (fixed in 1.2.0)
- Machothemes Antreas: before 1.0.7 (fixed in 1.0.7)
- Machothemes Medzone Lite: before 1.2.6 (fixed in 1.2.6)
- Machothemes Naturemag Lite: up to and including 1.0.4
- Machothemes Newsmag: before 2.4.2 (fixed in 2.4.2)
- Machothemes Regina Lite: before 2.0.6 (fixed in 2.0.6)
Published 2023-06-07. Last modified 2026-06-17.