A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to malicious file uploads via the plugin_offline_installer AJAX action due to a missing capability check in the plugin_offline_installer_callback function found in the /demo-functions.php file or /welcome.php file of the affected products. The complete list of affected products and their versions are below: WordPress Plugin: AccessPress Demo Importer <=1.0.6 WordPress Themes: accesspress-basic <= 3.2.1 accesspress-lite <= 2.92 accesspress-mag <= 2.6.5 accesspress-parallax <= 4.5 accesspress-root <= 2.5 accesspress-store <= 2.4.9 agency-lite <= 1.1.6 arrival <= 1.4.2 bingle <= 1.0.4 bloger <= 1.2.6 brovy <= 1.3 construction-lite <= 1.2.5 doko <= 1.0.27 edict-lite <= 1.1.4 eightlaw-lite <= 2.1.5 eightmedi-lite <= 2.1.8 eight-sec <= 1.1.4 eightstore-lite <= 1.2.5 enlighten <= 1.3.5 fotography <= 2.4.0 opstore <= 1.4.3 parallaxsome <= 1.3.6 punte <= 1.1.2 revolve <= 1.3.1 ripple <= 1.2.0 sakala <= 1.0.4 scrollme <= 2.1.0 storevilla <= 1.4.1 swing-lite <= 1.1.9 the100 <= 1.1.2 the-launcher <= 1.3.2 the-monday <= 1.4.1 ultra-seven <= 1.2.8 uncode-lite <= 1.3.3 vmag <= 1.2.7 vmagazine-lite <= 1.3.5 vmagazine-news <= 1.0.5 wpparallax <= 2.0.6 wp-store <= 1.1.9 zigcy-baby <= 1.0.6 zigcy-cosmetics <= 1.0.5 zigcy-lite <= 2.0.9
Project Subscriptions
| Vendors | Products |
|---|---|
|
Accesspressthemes
Subscribe
|
Access Demo Importer
Subscribe
Accesspress-lite
Subscribe
Accesspress-mag
Subscribe
Accesspress-parallax
Subscribe
Accesspress-root
Subscribe
Accesspress-store
Subscribe
Accesspress Basic
Subscribe
Agency-lite
Subscribe
Arrival
Subscribe
Bingle
Subscribe
Bloger
Subscribe
Brovy
Subscribe
Construction-lite
Subscribe
Doko
Subscribe
Edict-lite
Subscribe
Eight-sec
Subscribe
Eightlaw-lite
Subscribe
Eightmedi-lite
Subscribe
Eightstore-lite
Subscribe
Enlighten
Subscribe
Fotography
Subscribe
Opstore
Subscribe
Parallaxsome
Subscribe
Punte
Subscribe
Revolve
Subscribe
Ripple
Subscribe
Sakala
Subscribe
Scrollme
Subscribe
Storevilla
Subscribe
Swing-lite
Subscribe
The-launcher
Subscribe
The-monday
Subscribe
The100
Subscribe
Ultra-seven
Subscribe
Uncode-lite
Subscribe
Vmag
Subscribe
Vmagazine-lite
Subscribe
Vmagazine-news
Subscribe
Wp-store
Subscribe
Wpparallax
Subscribe
Zigcy-baby
Subscribe
Zigcy-cosmetics
Subscribe
Zigcy-lite
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-25678 | A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to malicious file uploads via the plugin_offline_installer AJAX action due to a missing capability check in the plugin_offline_installer_callback function found in the /demo-functions.php file or /welcome.php file of the affected products. The complete list of affected products and their versions are below: WordPress Plugin: AccessPress Demo Importer <=1.0.6 WordPress Themes: accesspress-basic <= 3.2.1 accesspress-lite <= 2.92 accesspress-mag <= 2.6.5 accesspress-parallax <= 4.5 accesspress-root <= 2.5 accesspress-store <= 2.4.9 agency-lite <= 1.1.6 arrival <= 1.4.2 bingle <= 1.0.4 bloger <= 1.2.6 brovy <= 1.3 construction-lite <= 1.2.5 doko <= 1.0.27 edict-lite <= 1.1.4 eightlaw-lite <= 2.1.5 eightmedi-lite <= 2.1.8 eight-sec <= 1.1.4 eightstore-lite <= 1.2.5 enlighten <= 1.3.5 fotography <= 2.4.0 opstore <= 1.4.3 parallaxsome <= 1.3.6 punte <= 1.1.2 revolve <= 1.3.1 ripple <= 1.2.0 sakala <= 1.0.4 scrollme <= 2.1.0 storevilla <= 1.4.1 swing-lite <= 1.1.9 the100 <= 1.1.2 the-launcher <= 1.3.2 the-monday <= 1.4.1 ultra-seven <= 1.2.8 uncode-lite <= 1.3.3 vmag <= 1.2.7 vmagazine-lite <= 1.3.5 vmagazine-news <= 1.0.5 wpparallax <= 2.0.6 wp-store <= 1.1.9 zigcy-baby <= 1.0.6 zigcy-cosmetics <= 1.0.5 zigcy-lite <= 2.0.9 |
Fixes
Solution
Update to the latest available version of software for each, or uninstall from WordPress site if no updated software available.
Workaround
No workaround given by the vendor.
References
History
Fri, 14 Feb 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-02-14T18:23:25.466Z
Reserved: 2021-08-20T00:00:00.000Z
Link: CVE-2021-39317
Updated: 2024-08-04T02:06:41.686Z
Status : Modified
Published: 2021-10-11T16:15:07.650
Modified: 2024-11-21T06:19:13.500
Link: CVE-2021-39317
No data.
OpenCVE Enrichment
No data.
EUVD