CVE Feed

    Dashboard / CVE / CVE-2021-39317

    CVE-2021-39317

    A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to malicious file uploads via the plugin_offline_installer AJAX action due to a missing capability check in the plugin_offline_installer_callback function found in the /demo-functions.php file or /welcome.php file of the affected products. The complete list of affected products and their versions are below: WordPress Plugin: AccessPress Demo Importer <=1.0.6 WordPress Themes: accesspress-basic <= 3.2.1 accesspress-lite <= 2.92 accesspress-mag <= 2.6.5 accesspress-parallax <= 4.5 accesspress-root <= 2.5 accesspress-store <= 2.4.9 agency-lite <= 1.1.6 arrival <= 1.4.2 bingle <= 1.0.4 bloger <= 1.2.6 brovy <= 1.3 construction-lite <= 1.2.5 doko <= 1.0.27 edict-lite <= 1.1.4 eightlaw-lite <= 2.1.5 eightmedi-lite <= 2.1.8 eight-sec <= 1.1.4 eightstore-lite <= 1.2.5 enlighten <= 1.3.5 fotography <= 2.4.0 opstore <= 1.4.3 parallaxsome <= 1.3.6 punte <= 1.1.2 revolve <= 1.3.1 ripple <= 1.2.0 sakala <= 1.0.4 scrollme <= 2.1.0 storevilla <= 1.4.1 swing-lite <= 1.1.9 the100 <= 1.1.2 the-launcher <= 1.3.2 the-monday <= 1.4.1 ultra-seven <= 1.2.8 uncode-lite <= 1.3.3 vmag <= 1.2.7 vmagazine-lite <= 1.3.5 vmagazine-news <= 1.0.5 wpparallax <= 2.0.6 wp-store <= 1.1.9 zigcy-baby <= 1.0.6 zigcy-cosmetics <= 1.0.5 zigcy-lite <= 2.0.9

    Published:Oct 11, 2021
    Last Modified:Feb 14, 2025
    EPS:Oct 11, 2021
    EPSS Score:0.00645
    CVSS Score:8.8

    Affected Products

    Vendor
    Accesspressthemes
    Product
    Access Demo Importer
    Vendor
    Accesspressthemes
    Product
    Accesspress-lite
    Vendor
    Accesspressthemes
    Product
    Accesspress-mag
    Vendor
    Accesspressthemes
    Product
    Accesspress-parallax
    Vendor
    Accesspressthemes
    Product
    Accesspress-root
    Vendor
    Accesspressthemes
    Product
    Accesspress-store
    Vendor
    Accesspressthemes
    Product
    Accesspress Basic
    Vendor
    Accesspressthemes
    Product
    Agency-lite
    Vendor
    Accesspressthemes
    Product
    Arrival
    Vendor
    Accesspressthemes
    Product
    Bingle
    Vendor
    Accesspressthemes
    Product
    Bloger
    Vendor
    Accesspressthemes
    Product
    Brovy
    Vendor
    Accesspressthemes
    Product
    Construction-lite
    Vendor
    Accesspressthemes
    Product
    Doko
    Vendor
    Accesspressthemes
    Product
    Edict-lite
    Vendor
    Accesspressthemes
    Product
    Eight-sec
    Vendor
    Accesspressthemes
    Product
    Eightlaw-lite
    Vendor
    Accesspressthemes
    Product
    Eightmedi-lite
    Vendor
    Accesspressthemes
    Product
    Eightstore-lite
    Vendor
    Accesspressthemes
    Product
    Enlighten
    Vendor
    Accesspressthemes
    Product
    Fotography
    Vendor
    Accesspressthemes
    Product
    Opstore
    Vendor
    Accesspressthemes
    Product
    Parallaxsome
    Vendor
    Accesspressthemes
    Product
    Punte
    Vendor
    Accesspressthemes
    Product
    Revolve
    Vendor
    Accesspressthemes
    Product
    Ripple
    Vendor
    Accesspressthemes
    Product
    Sakala
    Vendor
    Accesspressthemes
    Product
    Scrollme
    Vendor
    Accesspressthemes
    Product
    Storevilla
    Vendor
    Accesspressthemes
    Product
    Swing-lite
    Vendor
    Accesspressthemes
    Product
    The-launcher
    Vendor
    Accesspressthemes
    Product
    The-monday
    Vendor
    Accesspressthemes
    Product
    The100
    Vendor
    Accesspressthemes
    Product
    Ultra-seven
    Vendor
    Accesspressthemes
    Product
    Uncode-lite
    Vendor
    Accesspressthemes
    Product
    Vmag
    Vendor
    Accesspressthemes
    Product
    Vmagazine-lite
    Vendor
    Accesspressthemes
    Product
    Vmagazine-news
    Vendor
    Accesspressthemes
    Product
    Wp-store
    Vendor
    Accesspressthemes
    Product
    Wpparallax
    Vendor
    Accesspressthemes
    Product
    Zigcy-baby
    Vendor
    Accesspressthemes
    Product
    Zigcy-cosmetics
    Vendor
    Accesspressthemes
    Product
    Zigcy-lite

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High