wpchill Vulnerabilities and Affected Products
Vulnerabilities associated with Brilliance.
Products
Clear product- Download Monitor12 vulnerabilities
- Kali Forms — Contact Form & Drag-and-Drop Builder10 vulnerabilities
- Strong Testimonials7 vulnerabilities
- Modula Image Gallery – Photo Grid & Video Gallery6 vulnerabilities
- Image Photo Gallery Final Tiles Grid5 vulnerabilities
- Passster – Password Protect Pages and Content5 vulnerabilities
- download_monitor3 vulnerabilities
- Brilliance2 vulnerabilities
- Filr – Secure document library2 vulnerabilities
- Gallery PhotoBlocks (WordPress plugin)2 vulnerabilities
- Image Gallery – Photo Grid & Video Gallery2 vulnerabilities
- Qyrr – simply and modern QR-Code creation2 vulnerabilities
- Simple Restrict2 vulnerabilities
- simple_restrict2 vulnerabilities
- Affluent1 vulnerability
- Allegiant1 vulnerability
- CPO Companion1 vulnerability
- CPO Content Types1 vulnerability
- CPO Shortcodes1 vulnerability
- CPO Shortcodes (WordPress plugin)1 vulnerability
- Download Monitor (WordPress plugin)1 vulnerability
- Download Monitor plugin for WordPress1 vulnerability
- Gallery PhotoBlocks1 vulnerability
- imageseo1 vulnerability
- Lightbox – EverlightBox Gallery1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2020-36721MEDIUM | Epsilon Framework Themes (Various Versions) - Unauthenticated Plugin Activation/DeactivationThe Brilliance <= 1.2.7, Activello <= 1.4.0, and Newspaper X <= 1.3.1 themes for WordPress are vulnerable to Plugin Activation/Deactivation. This is due to the 'activello_activate_plugin' and 'activello_deactivate_plugin' functions in the 'inc/welcome-screen/class-activello-welcome.php' file missing capability and security checks/nonces. This makes it possible for unauthenticated attackers to activate and deactivate arbitrary plugins installed on a vulnerable site. | CVSS6.5v3.1 | EPSS0.979% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-36708CRITICAL | Epsilon Framework Themes (Various Versions) - Function InjectionThe following themes for WordPress are vulnerable to Function Injections in versions up to and including Shapely <= 1.2.7, NewsMag <= 2.4.1, Activello <= 1.4.0, Illdy <= 2.1.4, Allegiant <= 1.2.2, Newspaper X <= 1.3.1, Pixova Lite <= 2.0.5, Brilliance <= 1.2.7, MedZone Lite <= 1.2.4, Regina Lite <= 2.0.4, Transcend <= 1.1.8, Affluent <= 1.1.0, Bonkers <= 1.0.4, Antreas <= 1.0.2, Sparkling <= 2.4.8, and NatureMag Lite <= 1.0.4. This is due to epsilon_framework_ajax_action. This makes it possible … | CVSS9.8v3.1 | EPSS65.3% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |