CVE-2020-36721
The Brilliance <= 1.2.7, Activello <= 1.4.0, and Newspaper X <= 1.3.1 themes for WordPress are vulnerable to Plugin Activation/Deactivation. This is due to the 'activello_activate_plugin' and 'activello_deactivate_plugin' functions in the 'inc/welcome-screen/class-activello-welcome.php' file missing capability and security checks/nonces. This makes it possible for unauthenticated attackers to activate and deactivate arbitrary plugins installed on a vulnerable site.
Published:Jun 7, 2023
Last Modified:Apr 8, 2026
EPS:Jun 7, 2023
EPSS Score:0.00178
CVSS Score:6.5
Affected Products
Vendor
Product
Action
Vendor
Colorlib
Product
Activello
Colorlib
Activello
Vendor
Colorlib
Product
Bonkers
Colorlib
Bonkers
Vendor
Colorlib
Product
Illdy
Colorlib
Illdy
Vendor
Colorlib
Product
Newspaper X
Colorlib
Newspaper X
Vendor
Colorlib
Product
Pixova Lite
Colorlib
Pixova Lite
Vendor
Colorlib
Product
Shapely
Colorlib
Shapely
Vendor
Cpothemes
Product
Affluent
Cpothemes
Affluent
Vendor
Cpothemes
Product
Allegiant
Cpothemes
Allegiant
Vendor
Cpothemes
Product
Brilliance
Cpothemes
Brilliance
Vendor
Cpothemes
Product
Transcend
Cpothemes
Transcend
Vendor
Machothemes
Product
Antreas
Machothemes
Antreas
Vendor
Machothemes
Product
Medzone Lite
Machothemes
Medzone Lite
Vendor
Machothemes
Product
Naturemag Lite
Machothemes
Naturemag Lite
Vendor
Machothemes
Product
Newsmag
Machothemes
Newsmag
Vendor
Machothemes
Product
Regina Lite
Machothemes
Regina Lite
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
