Epsilon Framework Themes (Various Versions) - Function Injection
Affected versions: *-1.2.2; *-1.0.4; *-2.4.1; *-1.2.7; *-1.0.4; *-2.0.4; *-1.1.8; *-2.4.8
Vulnerability type: CWE-94 Improper Control of Generation of Code ('Code Injection')
Affected software, patched versions and attribution
The following themes for WordPress are vulnerable to Function Injections in versions up to and including Shapely <= 1.2.7, NewsMag <= 2.4.1, Activello <= 1.4.0, Illdy <= 2.1.4, Allegiant <= 1.2.2, Newspaper X <= 1.3.1, Pixova Lite <= 2.0.5, Brilliance <= 1.2.7, MedZone Lite <= 1.2.4, Regina Lite <= 2.0.4, Transcend <= 1.1.8, Affluent <= 1.1.0, Bonkers <= 1.0.4, Antreas <= 1.0.2, Sparkling <= 2.4.8, and NatureMag Lite <= 1.0.4. This is due to epsilon_framework_ajax_action. This makes it possible for unauthenticated attackers to call functions and achieve remote code execution.
Allegiant
Affected versions: *-1.2.2
Patched versions: 1.2.6
NatureMag Lite
Affected versions: *-1.0.4
Patched versions: 1.0.5
NewsMag
Affected versions: *-2.4.1
Patched versions: 2.4.2
Shapely
Affected versions: *-1.2.7
Patched versions: 1.2.9
Bonkers
Affected versions: *-1.0.4
Patched versions: 1.0.6
Regina Lite
Affected versions: *-2.0.4
Patched versions: 2.0.6
Transcend
Affected versions: *-1.1.8
Patched versions: 1.2.0
Sparkling
Affected versions: *-2.4.8
Patched versions: 2.4.9
Newspaper X
Affected versions: *-1.3.1
Patched versions: 1.3.2
Antreas
Affected versions: *-1.0.2
Patched versions: 1.0.7
Affluent
Affected versions: *-1.1.0
Patched versions: 1.1.2
Brilliance
Affected versions: *-1.2.7
Patched versions: 1.3.0
Activello
Affected versions: *-1.4.0
Patched versions: 1.4.2
Illdy
Affected versions: *-2.1.4
Patched versions: 2.1.7
MedZone Lite
Affected versions: *-1.2.4
Patched versions: 1.2.6
Pixova Lite
Affected versions: *-2.0.5
Patched versions: 2.0.7
Researcher credit: Jerome Bruandet
Applicable copyright and licence notices
This record contains material that is subject to copyright
Copyright 2012-2026 Defiant Inc.
Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.
This record contains material that is subject to copyright
Copyright 1999-2026 The MITRE Corporation
CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.
- Published
- October 1, 2020
- CVSS
- 9.8