PT-2023-11863 · Activello+1 · Activello+2

·

CVE-2020-36721

·

Published

2023-06-07

·

Updated

2023-06-16

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions The Brilliance versions prior to 1.2.8 Activello versions prior to 1.4.1 Newspaper X versions prior to 1.3.2
Description The issue is related to the lack of capability and security checks/nonces in the activello activate plugin and activello deactivate plugin functions, located in the inc/welcome-screen/class-activello-welcome.php file. This allows unauthenticated attackers to activate and deactivate arbitrary plugins installed on a vulnerable site.
Recommendations For The Brilliance version 1.2.7 and earlier, update to version 1.2.8 or later. For Activello version 1.4.0 and earlier, update to version 1.4.1 or later. For Newspaper X version 1.3.1 and earlier, update to version 1.3.2 or later.

Exploit

Fix

Missing Authorization

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-36721

Affected Products

Activello
Newspaper
The Brilliance