Description
The Brilliance <= 1.2.7, Activello <= 1.4.0, and Newspaper X <= 1.3.1 themes for WordPress are vulnerable to Plugin Activation/Deactivation. This is due to the 'activello_activate_plugin' and 'activello_deactivate_plugin' functions in the 'inc/welcome-screen/class-activello-welcome.php' file missing capability and security checks/nonces. This makes it possible for unauthenticated attackers to activate and deactivate arbitrary plugins installed on a vulnerable site.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-24163 | The Brilliance <= 1.2.7, Activello <= 1.4.0, and Newspaper X <= 1.3.1 themes for WordPress are vulnerable to Plugin Activation/Deactivation. This is due to the 'activello_activate_plugin' and 'activello_deactivate_plugin' functions in the 'inc/welcome-screen/class-activello-welcome.php' file missing capability and security checks/nonces. This makes it possible for unauthenticated attackers to activate and deactivate arbitrary plugins installed on a vulnerable site. |
References
History
Wed, 08 Apr 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Epsilon Framework Themes (Various Versions) - Unauthenticated Plugin Activation/Deactivation | |
| Weaknesses | CWE-284 |
Sat, 28 Dec 2024 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Subscriptions
Colorlib
Subscribe
Activello
Subscribe
Bonkers
Subscribe
Illdy
Subscribe
Newspaper X
Subscribe
Pixova Lite
Subscribe
Shapely
Subscribe
Cpothemes
Subscribe
Affluent
Subscribe
Allegiant
Subscribe
Brilliance
Subscribe
Transcend
Subscribe
Machothemes
Subscribe
Antreas
Subscribe
Medzone Lite
Subscribe
Naturemag Lite
Subscribe
Newsmag
Subscribe
Regina Lite
Subscribe
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:14:14.374Z
Reserved: 2023-06-06T13:07:21.267Z
Link: CVE-2020-36721
Updated: 2024-08-04T17:37:06.599Z
Status : Modified
Published: 2023-06-07T02:15:12.297
Modified: 2026-04-08T19:17:34.387
Link: CVE-2020-36721
No data.
OpenCVE Enrichment
No data.
EUVD