CVE-2020-36721: Colorlib Activello
Medium severity, CVSS 6.5. EPSS: 1% chance of exploitation in the next 30 days.
The Brilliance <= 1.2.7, Activello <= 1.4.0, and Newspaper X <= 1.3.1 themes for WordPress are vulnerable to Plugin Activation/Deactivation. This is due to the 'activello_activate_plugin' and 'activello_deactivate_plugin' functions in the 'inc/welcome-screen/class-activello-welcome.php' file missing capability and security checks/nonces. This makes it possible for unauthenticated attackers to activate and deactivate arbitrary plugins installed on a vulnerable site.
Affected products
- Colorlib Activello: before 1.4.2 (fixed in 1.4.2)
- Colorlib Bonkers: before 1.0.6 (fixed in 1.0.6)
- Colorlib Illdy: before 2.1.7 (fixed in 2.1.7)
- Colorlib Newspaper X: before 1.3.2 (fixed in 1.3.2)
- Colorlib Pixova Lite: before 2.0.7 (fixed in 2.0.7)
- Colorlib Shapely: before 1.2.9 (fixed in 1.2.9)
- Cpothemes Affluent: before 1.1.2 (fixed in 1.1.2)
- Cpothemes Allegiant: before 1.2.6 (fixed in 1.2.6)
- Cpothemes Brilliance: before 1.3.0 (fixed in 1.3.0)
- Cpothemes Transcend: before 1.2.0 (fixed in 1.2.0)
- Machothemes Antreas: before 1.0.7 (fixed in 1.0.7)
- Machothemes Medzone Lite: before 1.2.6 (fixed in 1.2.6)
- Machothemes Naturemag Lite: up to and including 1.0.4
- Machothemes Newsmag: before 2.4.2 (fixed in 2.4.2)
- Machothemes Regina Lite: before 2.0.6 (fixed in 2.0.6)
Published 2023-06-07. Last modified 2026-06-17.