First published: Wed Jun 07 2023(Updated: )
The Brilliance <= 1.2.7, Activello <= 1.4.0, and Newspaper X <= 1.3.1 themes for WordPress are vulnerable to Plugin Activation/Deactivation. This is due to the 'activello_activate_plugin' and 'activello_deactivate_plugin' functions in the 'inc/welcome-screen/class-activello-welcome.php' file missing capability and security checks/nonces. This makes it possible for unauthenticated attackers to activate and deactivate arbitrary plugins installed on a vulnerable site.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Colorlib Activello Theme | <1.4.2 | |
Colorlib Bonkers | <1.0.6 | |
Illdy | <2.1.7 | |
Colorlib Newspaper X | <1.3.2 | |
Colorlib Pixova Lite | <2.0.7 | |
Colorlib Shapely | <1.2.9 | |
Cpothemes Affluent | <1.1.2 | |
Cpothemes Allegiant | <1.2.6 | |
Cpothemes Brilliance | <1.3.0 | |
Cpothemes Transcend | <1.2.0 | |
Machothemes Antreas | <1.0.7 | |
Machothemes Medzone Lite | <1.2.6 | |
Machothemes Naturemag Lite | <=1.0.4 | |
Tagdiv Newsmag | <2.4.2 | |
Machothemes Regina Lite | <2.0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-36721 is categorized as a medium severity vulnerability due to unauthorized plugin activation and deactivation.
To fix CVE-2020-36721, update the affected themes to their latest versions where the vulnerability has been patched.
CVE-2020-36721 affects Cpothemes Brilliance versions up to 1.3.0 and several other themes including Activello, Newspaper X, and others.
CVE-2020-36721 allows an attacker to activate or deactivate plugins without proper authentication, leading to potential site compromise.
A temporary workaround for CVE-2020-36721 is to disable the affected theme's welcome screen functions if code access is available.