CVE-2021-39317

Severity CVSS v4.0:
Pending analysis
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
11/10/2021
Last modified:
09/12/2022

Description

A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to malicious file uploads via the plugin_offline_installer AJAX action due to a missing capability check in the plugin_offline_installer_callback function found in the /demo-functions.php file or /welcome.php file of the affected products. The complete list of affected products and their versions are below: WordPress Plugin: AccessPress Demo Importer

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:accesspressthemes:access_demo_importer:*:*:*:*:*:wordpress:*:* 1.0.7 (excluding)
cpe:2.3:a:accesspressthemes:accesspress-lite:*:*:*:*:*:wordpress:*:* 2.92 (including)
cpe:2.3:a:accesspressthemes:accesspress-mag:*:*:*:*:*:wordpress:*:* 2.6.5 (including)
cpe:2.3:a:accesspressthemes:accesspress-parallax:*:*:*:*:*:wordpress:*:* 4.5 (including)
cpe:2.3:a:accesspressthemes:accesspress-root:*:*:*:*:*:wordpress:*:* 2.5 (including)
cpe:2.3:a:accesspressthemes:accesspress-store:*:*:*:*:*:wordpress:*:* 2.4.9 (including)
cpe:2.3:a:accesspressthemes:accesspress_basic:*:*:*:*:*:wordpress:*:* 3.2.1 (including)
cpe:2.3:a:accesspressthemes:agency-lite:*:*:*:*:*:wordpress:*:* 1.1.6 (including)
cpe:2.3:a:accesspressthemes:arrival:*:*:*:*:*:wordpress:*:* 1.4.2 (including)
cpe:2.3:a:accesspressthemes:bingle:*:*:*:*:*:wordpress:*:* 1.0.4 (including)
cpe:2.3:a:accesspressthemes:bloger:*:*:*:*:*:wordpress:*:* 1.2.6 (including)
cpe:2.3:a:accesspressthemes:brovy:*:*:*:*:*:wordpress:*:* 1.3 (including)
cpe:2.3:a:accesspressthemes:construction-lite:*:*:*:*:*:wordpress:*:* 1.2.5 (including)
cpe:2.3:a:accesspressthemes:doko:*:*:*:*:*:wordpress:*:* 1.0.27 (including)
cpe:2.3:a:accesspressthemes:edict-lite:*:*:*:*:*:wordpress:*:* 1.1.4 (including)