6.5
CVSSv3

CVE-2020-36721

Published: 07/06/2023 Updated: 07/11/2023
CVSS v3 Base Score: 6.5 | Impact Score: 2.5 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

The Brilliance <= 1.2.7, Activello <= 1.4.0, and Newspaper X <= 1.3.1 themes for WordPress are vulnerable to Plugin Activation/Deactivation. This is due to the 'activello_activate_plugin' and 'activello_deactivate_plugin' functions in the 'inc/welcome-screen/class-activello-welcome.php' file missing capability and security checks/nonces. This makes it possible for unauthenticated malicious users to activate and deactivate arbitrary plugins installed on a vulnerable site.

Vulnerable Product Search on Vulmon Subscribe to Product

machothemes naturemag lite

machothemes antreas

colorlib bonkers

cpothemes affluent

cpothemes transcend

machothemes regina lite

cpothemes brilliance

machothemes medzone lite

colorlib pixova lite

colorlib newspaper x

cpothemes allegiant

colorlib illdy

colorlib activello

machothemes newsmag

colorlib shapely