Activello

Activello has 4 disclosed vulnerabilities in the WordSec catalog, reported between 2020 and 2022; all 4 are fixed as of September 2026. Their average CVSS score is 7.3, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 0 high. 2022 was the busiest year with 2 disclosures.

The most common weakness is Cross-Site Scripting, behind 2 of the records (50%). Other recurring categories include Code Injection, Improper Access Control.

Every one of the 4 issues recorded for Activello has a vendor fix available, so running the current release closes all known holes.

2 independent researchers contributed these findings, most of them (2) reported by Brandon James Roldan (tomorrowisnew). Activello is installed on roughly 4,000 WordPress sites, so each unpatched flaw has a wide blast radius.

Strategic Overview

Avg CVSSHigh
7.3/ 10
Patch Coverage100%
Open

0

Fixed

4

Get automatic notifications for all Activello vulnerabilities before they are exploited.

Highest severity on recordCVSS 9.8CVE-2020-36708

Epsilon Framework Themes (Various Versions) - Function Injection

Read the full analysis

Vulnerability Records

4 records
Activello screenshot
Latestv1.6.1
4.9(23)
98/100
Last Updated
2026-08-10 (1mo ago)
Active Installs
4,000+
Downloads
724,756
Requires WP
6.0+
Requires PHP
7.0+
Created
2016-03-15 (11y ago)

Activello is a clean and minimal WordPress blog theme with a premium look and feel, well suited for food, fashion, travel, lifestyle and any other beautiful blog. It ships a full-width featured slider, a widgetized sidebar, four layout options you can set globally or per post, and Customizer options for colours, header and footer with live preview. The front end is fully responsive, built on Bootstrap, and the theme's own JavaScript runs without jQuery. Activello is WooCommerce ready, SEO friendly, translation ready and comes with over twenty bundled translations.

Tags
BlogE commerceCustom logoCustom menuSticky postWide blocksBlock editor stylesEditor styleCustom colorsTheme optionsFeatured imagesCustom backgroundThreaded commentsTranslation readyFull width template

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C