Cpothemes develops a collection of WordPress themes (Allegiant, Affluent, Brilliance, Transcend, and others) that support website customization and presentation across small-to-medium deployments. The vulnerability exposure centers on application-layer access control and input-handling weaknesses, including improper authorization checks, code injection, cross-site scripting, and insufficient input sanitization in web page generation—defects characteristic of web-facing customization software. Current vulnerability counts, severity, and exploitation status are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cpothemes over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-36708CRITICAL The following themes for WordPress are vulnerable to Function Injections in versions up to and including Shapely <= 1.2.7, NewsMag <= 2.4.1, Activello <= 1.4.0, Illdy <= 2.1.4, All | Jun 7, 2023 | 9.8 | 74 | NO | YES |
CVE-2020-36721MEDIUM The Brilliance <= 1.2.7, Activello <= 1.4.0, and Newspaper X <= 1.3.1 themes for WordPress are vulnerable to Plugin Activation/Deactivation. This is due to the 'activello_activate_ | Jun 7, 2023 | 6.5 | 20 | NO | NO |
CVE-2024-43329MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP Chill Allegiant allegiant allows Stored XSS.This issue affects Alleg | Aug 18, 2024 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cpothemes.
Media articles that mention a CVE ID that affects a product developed by Cpothemes — matched by CVE ID, not by vendor name.