CVE-2021-39317
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD
Description
A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to malicious file uploads via the plugin_offline_installer AJAX action due to a missing capability check in the plugin_offline_installer_callback function found in the /demo-functions.php file or /welcome.php file of the affected products. The complete list of affected products and their versions are below: WordPress Plugin: AccessPress Demo Importer <=1.0.6 WordPress Themes: accesspress-basic <= 3.2.1 accesspress-lite <= 2.92 accesspress-mag <= 2.6.5 accesspress-parallax <= 4.5 accesspress-root <= 2.5 accesspress-store <= 2.4.9 agency-lite <= 1.1.6 arrival <= 1.4.2 bingle <= 1.0.4 bloger <= 1.2.6 brovy <= 1.3 construction-lite <= 1.2.5 doko <= 1.0.27 edict-lite <= 1.1.4 eightlaw-lite <= 2.1.5 eightmedi-lite <= 2.1.8 eight-sec <= 1.1.4 eightstore-lite <= 1.2.5 enlighten <= 1.3.5 fotography <= 2.4.0 opstore <= 1.4.3 parallaxsome <= 1.3.6 punte <= 1.1.2 revolve <= 1.3.1 ripple <= 1.2.0 sakala <= 1.0.4 scrollme <= 2.1.0 storevilla <= 1.4.1 swing-lite <= 1.1.9 the100 <= 1.1.2 the-launcher <= 1.3.2 the-monday <= 1.4.1 ultra-seven <= 1.2.8 uncode-lite <= 1.3.3 vmag <= 1.2.7 vmagazine-lite <= 1.3.5 vmagazine-news <= 1.0.5 wpparallax <= 2.0.6 wp-store <= 1.1.9 zigcy-baby <= 1.0.6 zigcy-cosmetics <= 1.0.5 zigcy-lite <= 2.0.9
Affected (43)
Products: Accesspressthemes: Access Demo Importer, Accesspress Lite, Accesspress Mag, Accesspress Parallax, Accesspress Root, Accesspress Store, Accesspress Basic, Agency Lite, Arrival, Bingle, Bloger, Brovy, Construction Lite, Doko, Edict Lite, Eight Sec, Eightlaw Lite, Eightmedi Lite, Eightstore Lite, Enlighten, Fotography, Opstore, Parallaxsome, Punte, Revolve, Ripple, Sakala, Scrollme, Storevilla, Swing Lite, The Launcher, The Monday, The100, Ultra Seven, Uncode Lite, Vmag, Vmagazine Lite, Vmagazine News, Wp Store, Wpparallax, Zigcy Baby, Zigcy Cosmetics, Zigcy Lite
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.0.7 | |
| Up to 2.92 | |
| Up to 2.6.5 | |
| Up to 4.5 | |
| Up to 2.5 | |
| Up to 2.4.9 | |
| Up to 3.2.1 | |
| Up to 1.1.6 | |
| Up to 1.4.2 | |
| Up to 1.0.4 | |
| Up to 1.2.6 | |
| Up to 1.3 | |
| Up to 1.2.5 | |
| Up to 1.0.27 | |
| Up to 1.1.4 | |
| Up to 1.1.4 | |
| Up to 2.1.5 | |
| Up to 2.1.8 | |
| Up to 1.2.5 | |
| Up to 1.3.5 | |
| Up to 2.4.0 | |
| Up to 1.4.3 | |
| Up to 1.3.6 | |
| Up to 1.1.2 | |
| Up to 1.3.1 | |
| Up to 1.2.0 | |
| Up to 1.0.4 | |
| Up to 2.1.0 | |
| Up to 1.4.1 | |
| Up to 1.1.9 | |
| Up to 1.3.2 | |
| Up to 1.4.1 | |
| Up to 1.1.2 | |
| Up to 1.2.8 | |
| Up to 1.3.3 | |
| Up to 1.2.7 | |
| Up to 1.3.5 | |
| Up to 1.0.5 | |
| Up to 1.1.9 | |
| Up to 2.0.6 | |
| Up to 1.0.6 | |
| Up to 1.0.5 | |
| Up to 2.0.9 |
Related CWEs
CWE-285
Improper Authorization
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
CWE-434
Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
References (8)
Source: security@wordfence.com
Third Party Advisory
Source: security@wordfence.com
PatchThird Party Advisory
Source: security@wordfence.com
PatchThird Party Advisory
Source: security@wordfence.com
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Timeline
No history available yet.