CVE-2020-36708: Epsilon Framework Themes (Various Versions) - Function Injection
The following themes for WordPress are vulnerable to Function Injections in versions up to and including Shapely <= 1.2.7, NewsMag <= 2.4.1, Activello <= 1.4.0, Illdy <= 2.1.4, Allegiant <= 1.2.2, Newspaper X <= 1.3.1, Pixova Lite <= 2.0.5, Brilliance <= 1.2.7, MedZone Lite <= 1.2.4, Regina Lite <= 2.0.4, Transcend <= 1.1.8, Affluent <= 1.1.0, Bonkers <= 1.0.4, Antreas <= 1.0.2, Sparkling <= 2.4.8, and NatureMag Lite <= 1.0.4. This is due to epsilonframeworkajaxaction. This makes it possible for unauthenticated attackers to call functions and achieve remote code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-36708?
CVE-2020-36708 is considered a medium severity vulnerability due to its potential for function injection attacks.
How do I fix CVE-2020-36708?
To fix CVE-2020-36708, update your WordPress theme to a version that is higher than the vulnerable versions listed in the CVE details.
Which WordPress themes are affected by CVE-2020-36708?
CVE-2020-36708 affects several themes including Shapely, NewsMag, Activello, Illdy, Allegiant, and others as detailed in the CVE report.
What types of attacks are possible with CVE-2020-36708?
Exploitation of CVE-2020-36708 can lead to unauthorized function injection, allowing attackers to execute arbitrary code on the affected site.
Are there any known exploits for CVE-2020-36708?
Yes, there are known exploits for CVE-2020-36708, which target the insecure themes and allow attackers to perform unauthorized actions.