CVE-2021-39317
Summary
| CVE | CVE-2021-39317 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-10-11 16:15:00 UTC |
| Updated | 2022-12-09 16:43:00 UTC |
| Description | A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to malicious file uploads via the plugin_offline_installer AJAX action due to a missing capability check in the plugin_offline_installer_callback function found in the /demo-functions.php file or /welcome.php file of the affected products. The complete list of affected products and their versions are below: WordPress Plugin: AccessPress Demo Importer <=1.0.6 WordPress Themes: accesspress-basic <= 3.2.1 accesspress-lite <= 2.92 accesspress-mag <= 2.6.5 accesspress-parallax <= 4.5 accesspress-root <= 2.5 accesspress-store <= 2.4.9 agency-lite <= 1.1.6 arrival <= 1.4.2 bingle <= 1.0.4 bloger <= 1.2.6 brovy <= 1.3 construction-lite <= 1.2.5 doko <= 1.0.27 edict-lite <= 1.1.4 eightlaw-lite <= 2.1.5 eightmedi-lite <= 2.1.8 eight-sec <= 1.1.4 eightstore-lite <= 1.2.5 enlighten <= 1.3.5 fotography <= 2.4.0 opstore <= 1.4.3 parallaxsome <= 1.3.6 punte <= 1.1.2 revolve <= 1.3.1 ripple <= 1.2.0 sakala <= 1.0.4 scrollme <= 2.1.0 storevilla <= 1.4.1 swing-lite <= 1.1.9 the100 <= 1.1.2 the-launcher <= 1.3.2 the-monday <= 1.4.1 ultra-seven <= 1.2.8 uncode-lite <= 1.3.3 vmag <= 1.2.7 vmagazine-lite <= 1.3.5 vmagazine-news <= 1.0.5 wpparallax <= 2.0.6 wp-store <= 1.1.9 zigcy-baby <= 1.0.6 zigcy-cosmetics <= 1.0.5 zigcy-lite <= 2.0.9 |
Risk And Classification
Problem Types: CWE-434
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Accesspressthemes | Accesspress-basic | All | All | All | All |
| Application | Accesspressthemes | Accesspress-lite | All | All | All | All |
| Application | Accesspressthemes | Accesspress-mag | All | All | All | All |
| Application | Accesspressthemes | Accesspress-parallax | All | All | All | All |
| Application | Accesspressthemes | Accesspress-root | All | All | All | All |
| Application | Accesspressthemes | Accesspress-store | All | All | All | All |
| Application | Accesspressthemes | Accesspress Basic | All | All | All | All |
| Application | Accesspressthemes | Access Demo Importer | All | All | All | All |
| Application | Accesspressthemes | Agency-lite | All | All | All | All |
| Application | Accesspressthemes | Arrival | All | All | All | All |
| Application | Accesspressthemes | Bingle | All | All | All | All |
| Application | Accesspressthemes | Bloger | All | All | All | All |
| Application | Accesspressthemes | Brovy | All | All | All | All |
| Application | Accesspressthemes | Construction-lite | All | All | All | All |
| Application | Accesspressthemes | Doko | All | All | All | All |
| Application | Accesspressthemes | Edict-lite | All | All | All | All |
| Application | Accesspressthemes | Eight-sec | All | All | All | All |
| Application | Accesspressthemes | Eightlaw-lite | All | All | All | All |
| Application | Accesspressthemes | Eightmedi-lite | All | All | All | All |
| Application | Accesspressthemes | Eightstore-lite | All | All | All | All |
| Application | Accesspressthemes | Enlighten | All | All | All | All |
| Application | Accesspressthemes | Fotography | All | All | All | All |
| Application | Accesspressthemes | Opstore | All | All | All | All |
| Application | Accesspressthemes | Parallaxsome | All | All | All | All |
| Application | Accesspressthemes | Punte | All | All | All | All |
| Application | Accesspressthemes | Revolve | All | All | All | All |
| Application | Accesspressthemes | Ripple | All | All | All | All |
| Application | Accesspressthemes | Sakala | All | All | All | All |
| Application | Accesspressthemes | Scrollme | All | All | All | All |
| Application | Accesspressthemes | Storevilla | All | All | All | All |
| Application | Accesspressthemes | Swing-lite | All | All | All | All |
| Application | Accesspressthemes | The-launcher | All | All | All | All |
| Application | Accesspressthemes | The-monday | All | All | All | All |
| Application | Accesspressthemes | The100 | All | All | All | All |
| Application | Accesspressthemes | Ultra-seven | All | All | All | All |
| Application | Accesspressthemes | Uncode-lite | All | All | All | All |
| Application | Accesspressthemes | Vmag | All | All | All | All |
| Application | Accesspressthemes | Vmagazine-lite | All | All | All | All |
| Application | Accesspressthemes | Vmagazine-news | All | All | All | All |
| Application | Accesspressthemes | Wp-store | All | All | All | All |
| Application | Accesspressthemes | Wpparallax | All | All | All | All |
| Application | Accesspressthemes | Zigcy-baby | All | All | All | All |
| Application | Accesspressthemes | Zigcy-cosmetics | All | All | All | All |
| Application | Accesspressthemes | Zigcy-lite | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 403 Forbidden | MISC | plugins.trac.wordpress.org | |
| 403 Forbidden | MISC | plugins.trac.wordpress.org | |
| Authenticated Vulnerability in Unpatched WordPress Themes - Patchstack | MISC | patchstack.com | |
| High Severity Vulnerability Patched in Access Demo Importer Plugin | MISC | www.wordfence.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Chloe Chamberland, Wordfence
LEGACY: Lenon Leite
There are currently no legacy QID mappings associated with this CVE.