CVE-2020-36708 is a critical function injection vulnerability affecting numerous WordPress themes developed by colorlib, cpothemes, and machothemes, including popular ones like Shapely and Sparkling, in versions up to 2.4.8. This flaw, stemming from the epsilon_framework_ajax_action, allows unauthenticated attackers to remotely execute code. With a CVSS score of 9.8 (Critical) and an EPSS score indicating high exploitability, it presents a significant risk due to its network-based attack vector, low complexity, and complete compromise potential (C, I, A: High). While not currently listed on the KEV catalog or showing active exploitation, a Nuclei template exists for detection, and its high FAUCET Risk Score of 99/100 underscores its severe threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.4.2CPE matchmatch criteria | cpe:2.3:a:colorlib:activello:*:*:*:*:*:wordpress:*:* | ||
< 1.0.6CPE matchmatch criteria | cpe:2.3:a:colorlib:bonkers:*:*:*:*:*:wordpress:*:* | ||
< 2.1.7CPE matchmatch criteria | cpe:2.3:a:colorlib:illdy:*:*:*:*:*:wordpress:*:* | ||
< 1.3.2CPE matchmatch criteria | cpe:2.3:a:colorlib:newspaper_x:*:*:*:*:*:wordpress:*:* | ||
< 2.0.7CPE matchmatch criteria | cpe:2.3:a:colorlib:pixova_lite:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.