CVE-2020-36708
The following themes for WordPress are vulnerable to Function Injections in versions up to and including Shapely <= 1.2.7, NewsMag <= 2.4.1, Activello <= 1.4.0, Illdy <= 2.1.4, Allegiant <= 1.2.2, Newspaper X <= 1.3.1, Pixova Lite <= 2.0.5, Brilliance <= 1.2.7, MedZone Lite <= 1.2.4, Regina Lite <= 2.0.4, Transcend <= 1.1.8, Affluent <= 1.1.0, Bonkers <= 1.0.4, Antreas <= 1.0.2, Sparkling <= 2.4.8, and NatureMag Lite <= 1.0.4. This is due to epsilon_framework_ajax_action. This makes it possible for unauthenticated attackers to call functions and achieve remote code execution.
Published:Jun 7, 2023
Last Modified:Apr 8, 2026
EPS:Jun 7, 2023
EPSS Score:0.90471
CVSS Score:9.8
Affected Products
Vendor
Product
Action
Vendor
Colorlib
Product
Activello
Colorlib
Activello
Vendor
Colorlib
Product
Bonkers
Colorlib
Bonkers
Vendor
Colorlib
Product
Illdy
Colorlib
Illdy
Vendor
Colorlib
Product
Newspaper X
Colorlib
Newspaper X
Vendor
Colorlib
Product
Pixova Lite
Colorlib
Pixova Lite
Vendor
Colorlib
Product
Shapely
Colorlib
Shapely
Vendor
Colorlib
Product
Sparklinkg
Colorlib
Sparklinkg
Vendor
Cpothemes
Product
Affluent
Cpothemes
Affluent
Vendor
Cpothemes
Product
Allegiant
Cpothemes
Allegiant
Vendor
Cpothemes
Product
Brilliance
Cpothemes
Brilliance
Vendor
Cpothemes
Product
Transcend
Cpothemes
Transcend
Vendor
Machothemes
Product
Antreas
Machothemes
Antreas
Vendor
Machothemes
Product
Medzone Lite
Machothemes
Medzone Lite
Vendor
Machothemes
Product
Naturemag Lite
Machothemes
Naturemag Lite
Vendor
Machothemes
Product
Newsmag
Machothemes
Newsmag
Vendor
Machothemes
Product
Regina Lite
Machothemes
Regina Lite
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
