Activello
Activello has 4 disclosed vulnerabilities in the WordSec catalog, reported between 2020 and 2022; all 4 are fixed as of September 2026. Their average CVSS score is 7.3, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 0 high. 2022 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Scripting, behind 2 of the records (50%). Other recurring categories include Code Injection, Improper Access Control.
Every one of the 4 issues recorded for Activello has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, most of them (2) reported by Brandon James Roldan (tomorrowisnew). Activello is installed on roughly 4,000 WordPress sites, so each unpatched flaw has a wide blast radius.
CVE-2020-36708Epsilon Framework Themes (Various Versions) - Function Injection
Read the full analysisVulnerability Records

Activello
Author
Silkalns
Activello is a clean and minimal WordPress blog theme with a premium look and feel, well suited for food, fashion, travel, lifestyle and any other beautiful blog. It ships a full-width featured slider, a widgetized sidebar, four layout options you can set globally or per post, and Customizer options for colours, header and footer with live preview. The front end is fully responsive, built on Bootstrap, and the theme's own JavaScript runs without jQuery. Activello is WooCommerce ready, SEO friendly, translation ready and comes with over twenty bundled translations.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C