← Back

CVE-2020-36721

nvd nist
Published: Jun 7, 2023Modified: Apr 8, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Exploitability: 3.9 / Impact: 2.5
Source: NVD

Description

The Brilliance <= 1.2.7, Activello <= 1.4.0, and Newspaper X <= 1.3.1 themes for WordPress are vulnerable to Plugin Activation/Deactivation. This is due to the 'activello_activate_plugin' and 'activello_deactivate_plugin' functions in the 'inc/welcome-screen/class-activello-welcome.php' file missing capability and security checks/nonces. This makes it possible for unauthenticated attackers to activate and deactivate arbitrary plugins installed on a vulnerable site.

Affected (15)

6 products
Activello
Bonkers
Illdy
Newspaper X
Pixova Lite
Shapely
4 products
Affluent
Allegiant
Brilliance
Transcend
5 products
Antreas
Medzone Lite
Naturemag Lite
Newsmag
Regina Lite
Configuration A
15 vulnerable
Vulnerable SoftwareAffected Versions
Before 1.4.2
Before 1.0.6
Before 2.1.7
Before 1.3.2
Before 2.0.7
Before 1.2.9
Before 1.1.2
Before 1.2.6
Before 1.3.0
Before 1.2.0
Before 1.0.7
Before 1.2.6
Up to 1.0.4
Before 2.4.2
Before 2.0.6

References (10)

Source: security@wordfence.com
Product
Source: security@wordfence.com
Product
Source: security@wordfence.com
Product
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Product
Source: af854a3a-2127-422b-91ae-364da2661108
Product
Source: af854a3a-2127-422b-91ae-364da2661108
Product

Timeline

No history available yet.