AccessPress Themes and Plugin <= Various Versions - Missing Authorization to Arbitrary Plugin Deactivation/Activation

Missing Authorization
CVE CVE-2022-23975
CVSS High (8.8)
Publicly Published January 11, 2022
Last Updated January 22, 2024
Researcher R3N0
Description

A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to unauthorized plugin deactivation and activation via the plugin_activation_callback and plugin_deactivate_callback functions called via AJAX actions that were missing capability checks and nonce validation. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to deactivate and activate arbitrary plugins. This could be used to deactivate security plugins and exploit other potential vulnerabilities.

References

43 affected software package

Software Type Theme
Software Slug the-monday (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.4.1
Patched Version
Software Type Theme
Software Slug doko (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.0.27
Patched Version
  • 1.1.0
Software Type Theme
Software Slug eight-sec (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.1.4
Patched Version
Software Type Theme
Software Slug revolve (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.3.1
Patched Version
Software Type Theme
Software Slug bingle (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.0.4
Patched Version
  • 1.0.5
Software Type Theme
Software Slug parallaxsome (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.3.6
Patched Version
  • 1.3.7
Software Type Theme
Software Slug uncode-lite (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.3.3
Patched Version
Software Type Theme
Software Slug eightlaw-lite (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 2.1.5
Patched Version
  • 2.1.6
Software Type Theme
Software Slug accesspress-lite (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 2.92
Patched Version
  • 2.93
Software Type Theme
Software Slug fotography (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 2.4.0
Patched Version
  • 2.4.1
Software Type Theme
Software Slug arrival (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.4.2
Patched Version
  • 1.4.3
Software Type Theme
Software Slug vmag (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.2.7
Patched Version
  • 1.2.8
Software Type Theme
Software Slug accesspress-mag (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 2.6.5
Patched Version
  • 2.6.6
Software Type Theme
Software Slug sakala (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.0.4
Patched Version
  • 1.0.5
Software Type Theme
Software Slug vmagazine-lite (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.3.5
Patched Version
  • 1.3.6
Software Type Theme
Software Slug digital-agency-lite (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.1.6
Patched Version
  • 1.1.7
Software Type Theme
Software Slug the-launcher (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.3.2
Patched Version
  • 1.3.3
Software Type Theme
Software Slug zigcy-lite (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 2.0.9
Patched Version
  • 2.1.0
Software Type Theme
Software Slug brovy (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.3
Patched Version
Software Type Theme
Software Slug eightmedi-lite (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 2.1.8
Patched Version
  • 2.1.9
Software Type Theme
Software Slug wpparallax (view on wordpress.org)
Patched? No
Affected Version
  • <= 2.0.6
Patched Version
Software Type Theme
Software Slug enlighten (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.3.5
Patched Version
  • 1.3.6
Software Type Theme
Software Slug eightstore-lite (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.2.5
Patched Version
  • 1.2.6
Software Type Theme
Software Slug accesspress-store (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 2.4.9
Patched Version
  • 2.5.0
Software Type Theme
Software Slug swing-lite (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.1.9
Patched Version
  • 1.2.0
Software Type Theme
Software Slug ripple (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.2.1
Patched Version
Software Type Plugin
Software Slug access-demo-importer (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.0.6
Patched Version
  • 1.0.7
Software Type Theme
Software Slug punte (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.1.2
Patched Version
  • 1.1.3
Software Type Theme
Software Slug accesspress-basic (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 3.2.1
Patched Version
  • 3.2.2
Software Type Theme
Software Slug zigcy-baby (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.0.6
Patched Version
  • 1.0.7
Software Type Theme
Software Slug scrollme (view on wordpress.org)
Patched? No
Affected Version
  • <= 2.1.0
Patched Version
Software Type Theme
Software Slug zigcy-cosmetics (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.0.5
Patched Version
  • 1.0.6
Software Type Theme
Software Slug construction-lite (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.2.5
Patched Version
  • 1.2.6
Software Type Theme
Software Slug vmagazine-news (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.0.5
Patched Version
  • 1.0.6
Software Type Theme
Software Slug accesspress-parallax-new (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 4.5
Patched Version
  • 4.6
Software Type Theme
Software Slug accesspress-root (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 2.5
Patched Version
  • 2.6.0
Software Type Theme
Software Slug storevilla (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.4.1
Patched Version
  • 1.4.2
Software Type Theme
Software Slug ultra-seven (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.2.8
Patched Version
Software Type Theme
Software Slug the100 (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.1.2
Patched Version
Software Type Theme
Software Slug edict-lite (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.1.4
Patched Version
Software Type Theme
Software Slug wp-store (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.1.9
Patched Version
  • 1.2.0
Software Type Theme
Software Slug opstore (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.4.3
Patched Version
  • 1.4.4
Software Type Theme
Software Slug bloger (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.2.6
Patched Version
  • 1.2.7
This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.
License: Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy. License Detail.