← Back

CVE-2020-36708

Published: Jun 7, 2023Modified: Apr 8, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

The following themes for WordPress are vulnerable to Function Injections in versions up to and including Shapely <= 1.2.7, NewsMag <= 2.4.1, Activello <= 1.4.0, Illdy <= 2.1.4, Allegiant <= 1.2.2, Newspaper X <= 1.3.1, Pixova Lite <= 2.0.5, Brilliance <= 1.2.7, MedZone Lite <= 1.2.4, Regina Lite <= 2.0.4, Transcend <= 1.1.8, Affluent <= 1.1.0, Bonkers <= 1.0.4, Antreas <= 1.0.2, Sparkling <= 2.4.8, and NatureMag Lite <= 1.0.4. This is due to epsilon_framework_ajax_action. This makes it possible for unauthenticated attackers to call functions and achieve remote code execution.

Affected (16)

7 products
Activello
Bonkers
Illdy
Newspaper X
Pixova Lite
Shapely
Sparklinkg
4 products
Affluent
Allegiant
Brilliance
Transcend
5 products
Antreas
Medzone Lite
Naturemag Lite
Newsmag
Regina Lite
Configuration A
16 vulnerable
Vulnerable SoftwareAffected Versions
Before 1.4.2
Before 1.0.6
Before 2.1.7
Before 1.3.2
Before 2.0.7
Before 1.2.9
Up to 2.4.8
Before 1.1.2
Before 1.2.6
Before 1.3.0
Before 1.2.0
Before 1.0.7
Before 1.2.6
Up to 1.0.4
Before 2.4.2
Before 2.0.6

References (10)

Source: security@wordfence.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.