theme

Sparkling Vulnerabilities

6 known security issues reported for the Sparkling WordPress theme. Most recent disclosed Mar 5, 2025.

1 critical 1 medium

Running Sparkling on your site? Check whether your installed version is affected.

Scan your site free

Sparkling [sparkling] < 2.4.10

unknown

[en] The Sparkling theme for WordPress is vulnerable to unauthorized plugin activation/deactivation due to a missing capability check on the 'sparkling_activate_plugin' and 'sparkling_deactivate_plugin' functions in versions up to, and including, 2.4.9. This makes it possible for unauthenticated attackers to activate/d...

Affected:
up to 2.4.10
Fixed in:
2.4.10
Disclosed:
Mar 5, 2025

CVE-2024-13423 on NVD →

Sparkling <= 2.4.9 - Missing Authorization to Unauthenticated Arbitrary Plugin Activation/Deactivation

medium

The Sparkling theme for WordPress is vulnerable to unauthorized plugin activation/deactivation due to a missing capability check on the 'sparkling_activate_plugin' and 'sparkling_deactivate_plugin' functions in versions up to, and including, 2.4.9. This makes it possible for unauthenticated attackers to activate/deacti...

CVSS:
5.3
Affected:
up to 2.4.9
Fixed in:
2.4.10
Disclosed:
Mar 4, 2025

CVE-2024-13423 on NVD →

Sparkling [sparkling] < 2.4.9

unknown

[en] The following themes for WordPress are vulnerable to Function Injections in versions up to and including Shapely <= 1.2.7, NewsMag <= 2.4.1, Activello <= 1.4.0, Illdy <= 2.1.4, Allegiant <= 1.2.2, Newspaper X <= 1.3.1, Pixova Lite <= 2.0.5, Brilliance <= 1.2.7, MedZone Lite <= 1.2.4, Regina Lite <= 2.0.4, Transcen...

Affected:
up to 2.4.9
Fixed in:
2.4.9
Disclosed:
Jun 7, 2023

CVE-2020-36708 on NVD →

Sparkling [sparkling] < 2.4.9

unknown

Unauthenticated Function Injection vulnerability discovered in WordPress Sparkling theme (versions <= 2.4.8) by NinTechNet.

Affected:
up to 2.4.9
Fixed in:
2.4.9
Disclosed:
Feb 10, 2022

Epsilon Framework Themes (Various Versions) - Function Injection

critical

The following themes for WordPress are vulnerable to Function Injections in versions up to and including Shapely <= 1.2.7, NewsMag <= 2.4.1, Activello <= 1.4.0, Illdy <= 2.1.4, Allegiant <= 1.2.2, Newspaper X <= 1.3.1, Pixova Lite <= 2.0.5, Brilliance <= 1.2.7, MedZone Lite <= 1.2.4, Regina Lite <= 2.0.4, Transcend <=...

CVSS:
9.8
Affected:
up to 2.4.8
Fixed in:
2.4.9
Disclosed:
Oct 1, 2020

CVE-2020-36708 on NVD →

Sparkling [sparkling] < 2.4.9

unknown

Jerome Bruandet, from nintechnet, discovered numerous themes affected by Unauthenticated Function Injection issues, due to the lack of capability and CSRF nonce checks in AJAX actions. The naturemag-lite theme partially fixed the issues in v1.0.5, however it has been removed from the WordPress repository. Three o...

Affected:
up to 2.4.9
Fixed in:
2.4.9

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database