← Back

CVE-2021-39317

nvd nist
Published: Oct 11, 2021Modified: Nov 21, 2024

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to malicious file uploads via the plugin_offline_installer AJAX action due to a missing capability check in the plugin_offline_installer_callback function found in the /demo-functions.php file or /welcome.php file of the affected products. The complete list of affected products and their versions are below: WordPress Plugin: AccessPress Demo Importer <=1.0.6 WordPress Themes: accesspress-basic <= 3.2.1 accesspress-lite <= 2.92 accesspress-mag <= 2.6.5 accesspress-parallax <= 4.5 accesspress-root <= 2.5 accesspress-store <= 2.4.9 agency-lite <= 1.1.6 arrival <= 1.4.2 bingle <= 1.0.4 bloger <= 1.2.6 brovy <= 1.3 construction-lite <= 1.2.5 doko <= 1.0.27 edict-lite <= 1.1.4 eightlaw-lite <= 2.1.5 eightmedi-lite <= 2.1.8 eight-sec <= 1.1.4 eightstore-lite <= 1.2.5 enlighten <= 1.3.5 fotography <= 2.4.0 opstore <= 1.4.3 parallaxsome <= 1.3.6 punte <= 1.1.2 revolve <= 1.3.1 ripple <= 1.2.0 sakala <= 1.0.4 scrollme <= 2.1.0 storevilla <= 1.4.1 swing-lite <= 1.1.9 the100 <= 1.1.2 the-launcher <= 1.3.2 the-monday <= 1.4.1 ultra-seven <= 1.2.8 uncode-lite <= 1.3.3 vmag <= 1.2.7 vmagazine-lite <= 1.3.5 vmagazine-news <= 1.0.5 wpparallax <= 2.0.6 wp-store <= 1.1.9 zigcy-baby <= 1.0.6 zigcy-cosmetics <= 1.0.5 zigcy-lite <= 2.0.9

Affected (43)

Access Demo Importer
Accesspress Lite
Accesspress Mag
Accesspress Parallax
Accesspress Root
Accesspress Store
Accesspress Basic
Agency Lite
Arrival
Bingle
Bloger
Brovy
Construction Lite
Doko
Edict Lite
Eight Sec
Eightlaw Lite
Eightmedi Lite
Eightstore Lite
Enlighten
Fotography
Opstore
Parallaxsome
Punte
Revolve
Ripple
Sakala
Scrollme
Storevilla
Swing Lite
The Launcher
The Monday
The100
Ultra Seven
Uncode Lite
Vmag
Vmagazine Lite
Vmagazine News
Wp Store
Wpparallax
Zigcy Baby
Zigcy Cosmetics
Zigcy Lite
Configuration A
43 vulnerable
Vulnerable SoftwareAffected Versions
Before 1.0.7
Up to 2.92
Up to 2.6.5
Up to 4.5
Up to 2.5
Up to 2.4.9
Up to 3.2.1
Up to 1.1.6
Up to 1.4.2
Up to 1.0.4
Up to 1.2.6
Up to 1.3
Up to 1.2.5
Up to 1.0.27
Up to 1.1.4
Up to 1.1.4
Up to 2.1.5
Up to 2.1.8
Up to 1.2.5
Up to 1.3.5
Up to 2.4.0
Up to 1.4.3
Up to 1.3.6
Up to 1.1.2
Up to 1.3.1
Up to 1.2.0
Up to 1.0.4
Up to 2.1.0
Up to 1.4.1
Up to 1.1.9
Up to 1.3.2
Up to 1.4.1
Up to 1.1.2
Up to 1.2.8
Up to 1.3.3
Up to 1.2.7
Up to 1.3.5
Up to 1.0.5
Up to 1.1.9
Up to 2.0.6
Up to 1.0.6
Up to 1.0.5
Up to 2.0.9

Timeline

No history available yet.