Input validation vulnerability in 16 Epsilon Framework Themes

Twenty-one WordPress themes have a security vulnerability that allows unauthenticated attackers to run code on a website. This affects versions up to and including Shapely 1.2.7, NewsMag 2.4.1, Activello 1.4.0, Illdy 2.1.4, Allegiant 1.2.2, Newspaper X 1.3.1, Pixova Lite 2.0.5, Brilliance 1.2.7, MedZone Lite 1.2.4, Regina Lite 2.0.4, Transcend 1.1.8, Affluent 1.1.0, Bonkers 1.0.4, Antreas 1.0.2, Sparkling 2.4.8, and NatureMag Lite 1.0.4. This security vulnerability is due to a flaw in the epsilon_framework_ajax_action.

Detected in:

Affluent fixed vulnerable versions: >= * <= 1.1.0
Antreas fixed vulnerable versions: >= * <= 1.0.2
Bonkers fixed vulnerable versions: >= * <= 1.0.4
Illdy fixed vulnerable versions: >= * <= 2.1.4
MedZone Lite fixed vulnerable versions: >= * <= 1.2.4
NatureMag Lite fixed vulnerable versions: >= * <= 1.0.4
Newspaper X fixed vulnerable versions: >= * <= 1.3.1
Pixova Lite fixed vulnerable versions: >= * <= 2.0.5
Shapely fixed vulnerable versions: >= * <= 1.2.7
Transcend fixed vulnerable versions: >= * <= 1.1.8
Activello open vulnerable versions: >= * <= 1.4.0
Allegiant open vulnerable versions: >= * <= 1.2.2
Brilliance open vulnerable versions: >= * <= 1.2.7
NewsMag open vulnerable versions: >= * <= 2.4.1
Regina Lite open vulnerable versions: >= * <= 2.0.4
Sparkling open vulnerable versions: >= * <= 2.4.8

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.