CVE-2020-36721: Epsilon Framework Themes (Various Versions) - Unauthenticated Plugin Activation/Deactivation
The Brilliance <= 1.2.7, Activello <= 1.4.0, and Newspaper X <= 1.3.1 themes for WordPress are vulnerable to Plugin Activation/Deactivation. This is due to the 'activelloactivateplugin' and 'activellodeactivateplugin' functions in the 'inc/welcome-screen/class-activello-welcome.php' file missing capability and security checks/nonces. This makes it possible for unauthenticated attackers to activate and deactivate arbitrary plugins installed on a vulnerable site.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-36721?
CVE-2020-36721 is categorized as a medium severity vulnerability due to unauthorized plugin activation and deactivation.
How do I fix CVE-2020-36721?
To fix CVE-2020-36721, update the affected themes to their latest versions where the vulnerability has been patched.
Which WordPress themes are affected by CVE-2020-36721?
CVE-2020-36721 affects Cpothemes Brilliance versions up to 1.3.0 and several other themes including Activello, Newspaper X, and others.
What kind of exploit is possible with CVE-2020-36721?
CVE-2020-36721 allows an attacker to activate or deactivate plugins without proper authentication, leading to potential site compromise.
Is there a workaround for CVE-2020-36721 while I update my theme?
A temporary workaround for CVE-2020-36721 is to disable the affected theme's welcome screen functions if code access is available.