Lucene search

K
nvd[email protected]NVD:CVE-2020-36721
HistoryJun 07, 2023 - 2:15 a.m.

CVE-2020-36721

2023-06-0702:15:12
CWE-862
web.nvd.nist.gov
3
wordpress
themes
vulnerability
pluginactivation
deactivation
unauthenticated attackers
cve-2020-36721
security checks
nonces

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

EPSS

0.002

Percentile

56.8%

The Brilliance <= 1.2.7, Activello <= 1.4.0, and Newspaper X <= 1.3.1 themes for WordPress are vulnerable to Plugin Activation/Deactivation. This is due to the ‘activello_activate_plugin’ and ‘activello_deactivate_plugin’ functions in the ‘inc/welcome-screen/class-activello-welcome.php’ file missing capability and security checks/nonces. This makes it possible for unauthenticated attackers to activate and deactivate arbitrary plugins installed on a vulnerable site.

Affected configurations

Nvd
Node
colorlibactivelloRange<1.4.2wordpress
OR
colorlibbonkersRange<1.0.6wordpress
OR
colorlibilldyRange<2.1.7wordpress
OR
colorlibnewspaper_xRange<1.3.2wordpress
OR
colorlibpixova_liteRange<2.0.7wordpress
OR
colorlibshapelyRange<1.2.9wordpress
OR
cpothemesaffluentRange<1.1.2wordpress
OR
cpothemesallegiantRange<1.2.6wordpress
OR
cpothemesbrillianceRange<1.3.0wordpress
OR
cpothemestranscendRange<1.2.0wordpress
OR
machothemesantreasRange<1.0.7wordpress
OR
machothemesmedzone_liteRange<1.2.6wordpress
OR
machothemesnaturemag_liteRange1.0.4wordpress
OR
machothemesnewsmagRange<2.4.2wordpress
OR
machothemesregina_liteRange<2.0.6wordpress
VendorProductVersionCPE
colorlibactivello*cpe:2.3:a:colorlib:activello:*:*:*:*:*:wordpress:*:*
colorlibbonkers*cpe:2.3:a:colorlib:bonkers:*:*:*:*:*:wordpress:*:*
colorlibilldy*cpe:2.3:a:colorlib:illdy:*:*:*:*:*:wordpress:*:*
colorlibnewspaper_x*cpe:2.3:a:colorlib:newspaper_x:*:*:*:*:*:wordpress:*:*
colorlibpixova_lite*cpe:2.3:a:colorlib:pixova_lite:*:*:*:*:*:wordpress:*:*
colorlibshapely*cpe:2.3:a:colorlib:shapely:*:*:*:*:*:wordpress:*:*
cpothemesaffluent*cpe:2.3:a:cpothemes:affluent:*:*:*:*:*:wordpress:*:*
cpothemesallegiant*cpe:2.3:a:cpothemes:allegiant:*:*:*:*:*:wordpress:*:*
cpothemesbrilliance*cpe:2.3:a:cpothemes:brilliance:*:*:*:*:*:wordpress:*:*
cpothemestranscend*cpe:2.3:a:cpothemes:transcend:*:*:*:*:*:wordpress:*:*
Rows per page:
1-10 of 151

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

EPSS

0.002

Percentile

56.8%

Related for NVD:CVE-2020-36721