S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Aug 19, 2025

CVE-2020-36708 Scanner

CVE-2020-36708 Scanner - Remote Code Execution (RCE) vulnerability in WordPress Epsilon Framework Themes

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3.4k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2020-36708
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

The following themes for WordPress are vulnerable to Function Injections in versions up to and including Shapely <= 1.2.7, NewsMag <= 2.4.1, Activello <= 1.4.0, Illdy <= 2.1.4, Allegiant <= 1.2.2, Newspaper X <= 1.3.1, Pixova Lite <= 2.0.5, Brilliance <= 1.2.7, MedZone Lite <= 1.2.4, Regina Lite <= 2.0.4, Transcend <= 1.1.8, Affluent <= 1.1.0, Bonkers <= 1.0.4, Antreas <= 1.0.2, Sparkling <= 2.4.8, and NatureMag Lite <= 1.0.4. This is due to epsilon_framework_ajax_action. This makes it possible for unauthenticated attackers to call functions and achieve remote code execution.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Antreasby machothemes
0
NatureMag Liteby machothemes
0
Bonkersby silkalns
0
Affluentby wpchill
0
Updated Aug 21, 2026View on NVD →
Detail

WordPress Epsilon Framework Themes are widely utilized across various WordPress sites to enhance design and functionality. These themes are popular among web developers for their customizable features, which allow for greater flexibility in site design. They are used in websites ranging from personal blogs to corporate sites, serving diverse purposes. The ease of use and compatibility with multiple plugins make them a favorite choice for many WordPress users. However, like any software, they can become outdated, and vulnerabilities may emerge if not regularly updated. The themes are managed by Colorlib, a notable provider in the WordPress theme industry.

The Remote Code Execution (RCE) vulnerability in the WordPress Epsilon Framework Themes allows unauthenticated attackers to execute arbitrary code. This vulnerability exploits the epsilon_framework_ajax_action function, permitting attackers to call functions remotely. Such vulnerabilities can lead to complete control of the affected WordPress site. The lack of authentication required for this exploit exacerbates the risk, making it a critical concern for site administrators. Developers have since addressed this vulnerability in newer updates to the themes.

Technical analysis reveals that the vulnerability is due to a function injection flaw. Specifically, the vulnerability exists in the 'epsilon_framework_ajax_action' endpoint within the affected themes. By manipulating the 'admin-ajax.php' endpoint, attackers can bypass authentication and execute arbitrary functions. The vulnerability allows for interaction with Interactsh Server to confirm exploitation. The vulnerable parameter in this context is the 'action' parameter, which is improperly filtered in older versions of the themes.

Exploitation of this vulnerability can result in severe consequences, such as a full site compromise. Attackers could potentially gain access to sensitive data, manipulate site content, and further deploy malicious code within the site's user environment. This could damage the site's reputation, disrupt operations, and lead to data breaches. It is imperative for site administrators to promptly secure their installations to prevent such outcomes.

REFERENCES

Solution Advice
  • Update the themes to the latest versions where the vulnerability is patched.
  • Monitor and apply security patches provided by theme developers promptly.
  • Regularly audit the site's security settings and configurations.
  • Back up the site regularly to ensure data can be restored in case of compromise.
  • Consider implementing a Web Application Firewall (WAF) to mitigate exploitation risks.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.