AccessPress Themes and Plugin <= Various Versions - Authenticated (Subscriber+) Arbitrary File Upload

Unrestricted Upload of File with Dangerous Type
CVE CVE-2021-39317
CVSS High (8.8)
Publicly Published October 6, 2021
Last Updated March 19, 2024
Researcher Chloe Chamberland, Lenon Leite, Lucio Sá
Description

A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to malicious file uploads via the plugin_offline_installer AJAX action due to a missing capability check in the plugin_offline_installer_callback function found in the /demo-functions.php file or /welcome.php file of the affected products.

References

44 affected software package

Software Type Theme
Software Slug the-monday (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.4.1
Patched Version
Software Type Theme
Software Slug doko (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.0.27
Patched Version
  • 1.1.0
Software Type Theme
Software Slug eight-sec (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.1.4
Patched Version
Software Type Theme
Software Slug revolve (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.3.1
Patched Version
Software Type Theme
Software Slug bingle (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.0.4
Patched Version
  • 1.0.5
Software Type Theme
Software Slug parallaxsome (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.3.6
Patched Version
  • 1.3.7
Software Type Theme
Software Slug uncode-lite (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.3.3
Patched Version
Software Type Theme
Software Slug eightlaw-lite (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 2.1.5
Patched Version
  • 2.1.6
Software Type Theme
Software Slug accesspress-lite (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 2.92
Patched Version
  • 2.93
Software Type Theme
Software Slug fotography (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 2.4.0
Patched Version
  • 2.4.1
Software Type Theme
Software Slug arrival (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.4.2
Patched Version
  • 1.4.3
Software Type Theme
Software Slug vmag (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.2.7
Patched Version
  • 1.2.8
Software Type Theme
Software Slug accesspress-mag (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 2.6.5
Patched Version
  • 2.6.6
Software Type Theme
Software Slug sakala (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.0.4
Patched Version
  • 1.0.5
Software Type Theme
Software Slug vmagazine-lite (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.3.5
Patched Version
  • 1.3.6
Software Type Theme
Software Slug digital-agency-lite (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.1.6
Patched Version
  • 1.1.7
Software Type Theme
Software Slug the-launcher (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.3.2
Patched Version
  • 1.3.3
Software Type Theme
Software Slug zigcy-lite (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 2.0.9
Patched Version
  • 2.1.0
Software Type Theme
Software Slug brovy (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.3
Patched Version
Software Type Theme
Software Slug eightmedi-lite (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 2.1.8
Patched Version
  • 2.1.9
Software Type Theme
Software Slug wpparallax (view on wordpress.org)
Patched? No
Affected Version
  • <= 2.0.6
Patched Version
Software Type Theme
Software Slug enlighten (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.3.5
Patched Version
  • 1.3.6
Software Type Theme
Software Slug eightstore-lite (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.2.5
Patched Version
  • 1.2.6
Software Type Theme
Software Slug accesspress-store (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 2.4.9
Patched Version
  • 2.5.0
Software Type Theme
Software Slug swing-lite (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.1.9
Patched Version
  • 1.2.0
Software Type Theme
Software Slug ripple (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.2.1
Patched Version
Software Type Plugin
Software Slug access-demo-importer (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.0.6
Patched Version
  • 1.0.7
Software Type Theme
Software Slug punte (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.1.2
Patched Version
  • 1.1.3
Software Type Theme
Software Slug accesspress-basic (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 3.2.1
Patched Version
  • 3.2.2
Software Type Theme
Software Slug zigcy-baby (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.0.6
Patched Version
  • 1.0.7
Software Type Theme
Software Slug scrollme (view on wordpress.org)
Patched? No
Affected Version
  • <= 2.1.0
Patched Version
Software Type Theme
Software Slug zigcy-cosmetics (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.0.5
Patched Version
  • 1.0.6
Software Type Theme
Software Slug construction-lite (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.2.5
Patched Version
  • 1.2.6
Software Type Theme
Software Slug vmagazine-news (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.0.5
Patched Version
  • 1.0.6
Software Type Theme
Software Slug accesspress-parallax-new (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 4.5
Patched Version
  • 4.6
Software Type Theme
Software Slug accesspress-root (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 2.5
Patched Version
  • 2.6.0
Software Type Theme
Software Slug accesspress-staple (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.9.1
Patched Version
Software Type Theme
Software Slug storevilla (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.4.1
Patched Version
  • 1.4.2
Software Type Theme
Software Slug ultra-seven (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.2.8
Patched Version
Software Type Theme
Software Slug the100 (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.1.2
Patched Version
Software Type Theme
Software Slug edict-lite (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.1.4
Patched Version
Software Type Theme
Software Slug wp-store (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.1.9
Patched Version
  • 1.2.0
Software Type Theme
Software Slug opstore (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.4.3
Patched Version
  • 1.4.4
Software Type Theme
Software Slug bloger (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.2.6
Patched Version
  • 1.2.7
This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.
License: Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy. License Detail.