← Back to browse · API

CVE-2020-36708

Severity
CRITICAL
CVSS
9.8
EPSS
0.65342
Risk score
62.07
CISA KEV
No
PoC
No
Published
2023-06-07
Modified
2026-04-08
First seen
2026-08-07
Aliases
EUVD-2020-24150, GHSA-48H4-C5MW-4H8J
Products
Macho Themes:NewsMag 0 ≤2.4.1, Macho Themes:Regina Lite 0 ≤2.0.4, WP Chill:Allegiant 0 ≤1.2.2, WP Chill:Brilliance 0 ≤1.2.7, WPChill:Affluent 0 ≤1.1.0, WPChill:Transcend 0 ≤1.1.8, machothemes:Antreas 0 ≤1.0.2, machothemes:MedZone Lite 0 ≤1.2.4, machothemes:NatureMag Lite 0 ≤1.0.4, silkalns:Activello 0 ≤1.4.0, silkalns:Bonkers 0 ≤1.0.4, silkalns:Illdy 0 ≤2.1.4, silkalns:Newspaper X 0 ≤1.3.1, silkalns:Pixova Lite 0 ≤2.0.5, silkalns:Shapely 0 ≤1.2.7, silkalns:Sparkling 0 ≤2.4.8
Sources
euvd EUVD-2020-24150

Description

The following themes for WordPress are vulnerable to Function Injections in versions up to and including Shapely <= 1.2.7, NewsMag <= 2.4.1, Activello <= 1.4.0, Illdy <= 2.1.4, Allegiant <= 1.2.2, Newspaper X <= 1.3.1, Pixova Lite <= 2.0.5, Brilliance <= 1.2.7, MedZone Lite <= 1.2.4, Regina Lite <= 2.0.4, Transcend <= 1.1.8, Affluent <= 1.1.0, Bonkers <= 1.0.4, Antreas <= 1.0.2, Sparkling <= 2.4.8, and NatureMag Lite <= 1.0.4. This is due to epsilon_framework_ajax_action. This makes it possible for unauthenticated attackers to call functions and achieve remote code execution.

References