CVE-2020-36721: Colorlib Activello

Medium severity, CVSS 6.5. EPSS: 1% chance of exploitation in the next 30 days.

The Brilliance <= 1.2.7, Activello <= 1.4.0, and Newspaper X <= 1.3.1 themes for WordPress are vulnerable to Plugin Activation/Deactivation. This is due to the 'activello_activate_plugin' and 'activello_deactivate_plugin' functions in the 'inc/welcome-screen/class-activello-welcome.php' file missing capability and security checks/nonces. This makes it possible for unauthenticated attackers to activate and deactivate arbitrary plugins installed on a vulnerable site.

Affected products

  • Colorlib Activello: before 1.4.2 (fixed in 1.4.2)
  • Colorlib Bonkers: before 1.0.6 (fixed in 1.0.6)
  • Colorlib Illdy: before 2.1.7 (fixed in 2.1.7)
  • Colorlib Newspaper X: before 1.3.2 (fixed in 1.3.2)
  • Colorlib Pixova Lite: before 2.0.7 (fixed in 2.0.7)
  • Colorlib Shapely: before 1.2.9 (fixed in 1.2.9)
  • Cpothemes Affluent: before 1.1.2 (fixed in 1.1.2)
  • Cpothemes Allegiant: before 1.2.6 (fixed in 1.2.6)
  • Cpothemes Brilliance: before 1.3.0 (fixed in 1.3.0)
  • Cpothemes Transcend: before 1.2.0 (fixed in 1.2.0)
  • Machothemes Antreas: before 1.0.7 (fixed in 1.0.7)
  • Machothemes Medzone Lite: before 1.2.6 (fixed in 1.2.6)
  • Machothemes Naturemag Lite: up to and including 1.0.4
  • Machothemes Newsmag: before 2.4.2 (fixed in 2.4.2)
  • Machothemes Regina Lite: before 2.0.6 (fixed in 2.0.6)

Published 2023-06-07. Last modified 2026-06-17.