Vulnerability Details CVE-2021-39317
A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to malicious file uploads via the plugin_offline_installer AJAX action due to a missing capability check in the plugin_offline_installer_callback function found in the /demo-functions.php file or /welcome.php file of the affected products. The complete list of affected products and their versions are below: WordPress Plugin: AccessPress Demo Importer <=1.0.6 WordPress Themes: accesspress-basic <= 3.2.1 accesspress-lite <= 2.92 accesspress-mag <= 2.6.5 accesspress-parallax <= 4.5 accesspress-root <= 2.5 accesspress-store <= 2.4.9 agency-lite <= 1.1.6 arrival <= 1.4.2 bingle <= 1.0.4 bloger <= 1.2.6 brovy <= 1.3 construction-lite <= 1.2.5 doko <= 1.0.27 edict-lite <= 1.1.4 eightlaw-lite <= 2.1.5 eightmedi-lite <= 2.1.8 eight-sec <= 1.1.4 eightstore-lite <= 1.2.5 enlighten <= 1.3.5 fotography <= 2.4.0 opstore <= 1.4.3 parallaxsome <= 1.3.6 punte <= 1.1.2 revolve <= 1.3.1 ripple <= 1.2.0 sakala <= 1.0.4 scrollme <= 2.1.0 storevilla <= 1.4.1 swing-lite <= 1.1.9 the100 <= 1.1.2 the-launcher <= 1.3.2 the-monday <= 1.4.1 ultra-seven <= 1.2.8 uncode-lite <= 1.3.3 vmag <= 1.2.7 vmagazine-lite <= 1.3.5 vmagazine-news <= 1.0.5 wpparallax <= 2.0.6 wp-store <= 1.1.9 zigcy-baby <= 1.0.6 zigcy-cosmetics <= 1.0.5 zigcy-lite <= 2.0.9
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 69.7%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 6.5
Products affected by CVE-2021-39317
-
cpe:2.3:a:accesspressthemes:access_demo_importer:-
-
cpe:2.3:a:accesspressthemes:access_demo_importer:1.0.0
-
cpe:2.3:a:accesspressthemes:access_demo_importer:1.0.1
-
cpe:2.3:a:accesspressthemes:access_demo_importer:1.0.2
-
cpe:2.3:a:accesspressthemes:access_demo_importer:1.0.3
-
cpe:2.3:a:accesspressthemes:access_demo_importer:1.0.4
-
cpe:2.3:a:accesspressthemes:access_demo_importer:1.0.5
-
cpe:2.3:a:accesspressthemes:access_demo_importer:1.0.6
-
cpe:2.3:a:accesspressthemes:accesspress-lite:*
-
cpe:2.3:a:accesspressthemes:accesspress-mag:*
-
cpe:2.3:a:accesspressthemes:accesspress-parallax:*
-
cpe:2.3:a:accesspressthemes:accesspress-root:*
-
cpe:2.3:a:accesspressthemes:accesspress-store:*
-
cpe:2.3:a:accesspressthemes:accesspress_basic:1.0
-
cpe:2.3:a:accesspressthemes:accesspress_basic:1.1.1
-
cpe:2.3:a:accesspressthemes:accesspress_basic:1.1.2
-
cpe:2.3:a:accesspressthemes:accesspress_basic:1.1.4
-
cpe:2.3:a:accesspressthemes:accesspress_basic:1.1.5
-
cpe:2.3:a:accesspressthemes:accesspress_basic:1.1.6
-
cpe:2.3:a:accesspressthemes:accesspress_basic:1.1.7
-
cpe:2.3:a:accesspressthemes:accesspress_basic:1.1.8
-
cpe:2.3:a:accesspressthemes:accesspress_basic:1.1.9
-
cpe:2.3:a:accesspressthemes:accesspress_basic:2.0.0
-
cpe:2.3:a:accesspressthemes:accesspress_basic:2.0.1
-
cpe:2.3:a:accesspressthemes:accesspress_basic:2.0.2
-
cpe:2.3:a:accesspressthemes:accesspress_basic:2.0.3
-
cpe:2.3:a:accesspressthemes:accesspress_basic:2.0.4
-
cpe:2.3:a:accesspressthemes:accesspress_basic:2.0.5
-
cpe:2.3:a:accesspressthemes:accesspress_basic:2.0.6
-
cpe:2.3:a:accesspressthemes:accesspress_basic:2.0.7
-
cpe:2.3:a:accesspressthemes:accesspress_basic:2.0.8
-
cpe:2.3:a:accesspressthemes:accesspress_basic:2.0.9
-
cpe:2.3:a:accesspressthemes:accesspress_basic:3.0.0
-
cpe:2.3:a:accesspressthemes:accesspress_basic:3.0.1
-
cpe:2.3:a:accesspressthemes:accesspress_basic:3.0.2
-
cpe:2.3:a:accesspressthemes:accesspress_basic:3.0.3
-
cpe:2.3:a:accesspressthemes:accesspress_basic:3.0.4
-
cpe:2.3:a:accesspressthemes:accesspress_basic:3.0.5
-
cpe:2.3:a:accesspressthemes:accesspress_basic:3.0.6
-
cpe:2.3:a:accesspressthemes:accesspress_basic:3.0.7
-
cpe:2.3:a:accesspressthemes:accesspress_basic:3.0.8
-
cpe:2.3:a:accesspressthemes:accesspress_basic:3.0.9
-
cpe:2.3:a:accesspressthemes:accesspress_basic:3.1.0
-
cpe:2.3:a:accesspressthemes:accesspress_basic:3.1.1
-
cpe:2.3:a:accesspressthemes:accesspress_basic:3.1.2
-
cpe:2.3:a:accesspressthemes:accesspress_basic:3.1.3
-
cpe:2.3:a:accesspressthemes:accesspress_basic:3.1.4
-
cpe:2.3:a:accesspressthemes:accesspress_basic:3.1.5
-
cpe:2.3:a:accesspressthemes:accesspress_basic:3.1.6
-
cpe:2.3:a:accesspressthemes:accesspress_basic:3.1.7
-
cpe:2.3:a:accesspressthemes:accesspress_basic:3.1.8
-
cpe:2.3:a:accesspressthemes:accesspress_basic:3.1.9
-
cpe:2.3:a:accesspressthemes:accesspress_basic:3.2.0
-
cpe:2.3:a:accesspressthemes:accesspress_basic:3.2.1
-
cpe:2.3:a:accesspressthemes:agency-lite:*
-
cpe:2.3:a:accesspressthemes:arrival:*
-
cpe:2.3:a:accesspressthemes:bingle:1.0.4
-
cpe:2.3:a:accesspressthemes:bloger:1.2.6
-
cpe:2.3:a:accesspressthemes:brovy:*
-
cpe:2.3:a:accesspressthemes:construction-lite:*
-
cpe:2.3:a:accesspressthemes:doko:1.0.27
-
cpe:2.3:a:accesspressthemes:edict-lite:*
-
cpe:2.3:a:accesspressthemes:eight-sec:*
-
cpe:2.3:a:accesspressthemes:eightlaw-lite:*
-
cpe:2.3:a:accesspressthemes:eightmedi-lite:*
-
cpe:2.3:a:accesspressthemes:eightstore-lite:1.0.0
-
cpe:2.3:a:accesspressthemes:eightstore-lite:1.0.1
-
cpe:2.3:a:accesspressthemes:eightstore-lite:1.0.2
-
cpe:2.3:a:accesspressthemes:eightstore-lite:1.0.3
-
cpe:2.3:a:accesspressthemes:eightstore-lite:1.0.4
-
cpe:2.3:a:accesspressthemes:eightstore-lite:1.0.50
-
cpe:2.3:a:accesspressthemes:eightstore-lite:1.0.51
-
cpe:2.3:a:accesspressthemes:eightstore-lite:1.0.52
-
cpe:2.3:a:accesspressthemes:eightstore-lite:1.0.53
-
cpe:2.3:a:accesspressthemes:eightstore-lite:1.0.54
-
cpe:2.3:a:accesspressthemes:eightstore-lite:1.0.55
-
cpe:2.3:a:accesspressthemes:eightstore-lite:1.0.56
-
cpe:2.3:a:accesspressthemes:eightstore-lite:1.0.57
-
cpe:2.3:a:accesspressthemes:eightstore-lite:1.0.58
-
cpe:2.3:a:accesspressthemes:eightstore-lite:1.0.59
-
cpe:2.3:a:accesspressthemes:eightstore-lite:1.0.60
-
cpe:2.3:a:accesspressthemes:eightstore-lite:1.0.61
-
cpe:2.3:a:accesspressthemes:eightstore-lite:1.0.62
-
cpe:2.3:a:accesspressthemes:eightstore-lite:1.0.63
-
cpe:2.3:a:accesspressthemes:eightstore-lite:1.0.64
-
cpe:2.3:a:accesspressthemes:eightstore-lite:1.0.65
-
cpe:2.3:a:accesspressthemes:eightstore-lite:1.0.66
-
cpe:2.3:a:accesspressthemes:eightstore-lite:1.0.67
-
cpe:2.3:a:accesspressthemes:eightstore-lite:1.0.68
-
cpe:2.3:a:accesspressthemes:eightstore-lite:1.0.69
-
cpe:2.3:a:accesspressthemes:eightstore-lite:1.0.70
-
cpe:2.3:a:accesspressthemes:eightstore-lite:1.0.71
-
cpe:2.3:a:accesspressthemes:eightstore-lite:1.0.72
-
cpe:2.3:a:accesspressthemes:eightstore-lite:1.0.73
-
cpe:2.3:a:accesspressthemes:eightstore-lite:1.0.74
-
cpe:2.3:a:accesspressthemes:eightstore-lite:1.0.75
-
cpe:2.3:a:accesspressthemes:eightstore-lite:1.0.76
-
cpe:2.3:a:accesspressthemes:eightstore-lite:1.0.77
-
cpe:2.3:a:accesspressthemes:eightstore-lite:1.0.78
-
cpe:2.3:a:accesspressthemes:eightstore-lite:1.0.79
-
cpe:2.3:a:accesspressthemes:eightstore-lite:1.0.80
-
cpe:2.3:a:accesspressthemes:eightstore-lite:1.0.81
-
cpe:2.3:a:accesspressthemes:eightstore-lite:1.0.82
-
cpe:2.3:a:accesspressthemes:eightstore-lite:1.0.83
-
cpe:2.3:a:accesspressthemes:eightstore-lite:1.0.84
-
cpe:2.3:a:accesspressthemes:eightstore-lite:1.0.85
-
cpe:2.3:a:accesspressthemes:eightstore-lite:1.0.86
-
cpe:2.3:a:accesspressthemes:eightstore-lite:1.0.87
-
cpe:2.3:a:accesspressthemes:eightstore-lite:1.0.88
-
cpe:2.3:a:accesspressthemes:eightstore-lite:1.0.89
-
cpe:2.3:a:accesspressthemes:eightstore-lite:1.0.90
-
cpe:2.3:a:accesspressthemes:eightstore-lite:1.0.91
-
cpe:2.3:a:accesspressthemes:eightstore-lite:1.0.92
-
cpe:2.3:a:accesspressthemes:eightstore-lite:1.0.93
-
cpe:2.3:a:accesspressthemes:eightstore-lite:1.0.94
-
cpe:2.3:a:accesspressthemes:eightstore-lite:1.1.0
-
cpe:2.3:a:accesspressthemes:eightstore-lite:1.1.1
-
cpe:2.3:a:accesspressthemes:eightstore-lite:1.1.2
-
cpe:2.3:a:accesspressthemes:eightstore-lite:1.1.3
-
cpe:2.3:a:accesspressthemes:eightstore-lite:1.1.4
-
cpe:2.3:a:accesspressthemes:eightstore-lite:1.2.0
-
cpe:2.3:a:accesspressthemes:eightstore-lite:1.2.1
-
cpe:2.3:a:accesspressthemes:eightstore-lite:1.2.2
-
cpe:2.3:a:accesspressthemes:eightstore-lite:1.2.3
-
cpe:2.3:a:accesspressthemes:eightstore-lite:1.2.4
-
cpe:2.3:a:accesspressthemes:eightstore-lite:1.2.5
-
cpe:2.3:a:accesspressthemes:enlighten:1.3.5
-
cpe:2.3:a:accesspressthemes:fotography:*
-
cpe:2.3:a:accesspressthemes:opstore:*
-
cpe:2.3:a:accesspressthemes:parallaxsome:*
-
cpe:2.3:a:accesspressthemes:punte:*
-
cpe:2.3:a:accesspressthemes:revolve:*
-
cpe:2.3:a:accesspressthemes:ripple:*
-
cpe:2.3:a:accesspressthemes:sakala:*
-
cpe:2.3:a:accesspressthemes:scrollme:*
-
cpe:2.3:a:accesspressthemes:storevilla:*
-
cpe:2.3:a:accesspressthemes:swing-lite:*
-
cpe:2.3:a:accesspressthemes:the-launcher:*
-
cpe:2.3:a:accesspressthemes:the-monday:*
-
cpe:2.3:a:accesspressthemes:the100:*
-
cpe:2.3:a:accesspressthemes:ultra-seven:*
-
cpe:2.3:a:accesspressthemes:uncode-lite:*
-
cpe:2.3:a:accesspressthemes:vmag:*
-
cpe:2.3:a:accesspressthemes:vmagazine-lite:*
-
cpe:2.3:a:accesspressthemes:vmagazine-news:*
-
cpe:2.3:a:accesspressthemes:wp-store:*
-
cpe:2.3:a:accesspressthemes:wpparallax:*
-
cpe:2.3:a:accesspressthemes:zigcy-baby:*
-
cpe:2.3:a:accesspressthemes:zigcy-cosmetics:*
-
cpe:2.3:a:accesspressthemes:zigcy-lite:*