The following themes for WordPress are vulnerable to Function Injections in versions up to and including Shapely <= 1.2.7, NewsMag <= 2.4.1, Activello <= 1.4.0, Illdy <= 2.1.4, Allegiant <= 1.2.2, Newspaper X <= 1.3.1, Pixova Lite <= 2.0.5, Brilliance <= 1.2.7, MedZone Lite <= 1.2.4, Regina Lite <= 2.0.4, Transcend <= 1.1.8, Affluent <= 1.1.0, Bonkers <= 1.0.4, Antreas <= 1.0.2, Sparkling <= 2.4.8, and NatureMag Lite <= 1.0.4. This is due to epsilon_framework_ajax_action. This makes it possible for unauthenticated malicious users to call functions and achieve remote code execution.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
machothemes naturemag lite |
||
colorlib sparklinkg |
||
machothemes antreas |
||
colorlib bonkers |
||
cpothemes affluent |
||
cpothemes transcend |
||
machothemes regina lite |
||
cpothemes brilliance |
||
machothemes medzone lite |
||
colorlib pixova lite |
||
colorlib newspaper x |
||
cpothemes allegiant |
||
colorlib illdy |
||
colorlib activello |
||
machothemes newsmag |
||
colorlib shapely |