CVE List

CVE-2021-39317

Critical 8.8

Versions up to, and including, 1.0.6, of the Access Demo Importer WordPress plugin are vulnerable to arbitrary file uploads via the plugin_offline_installer AJAX action due to a missing capability check in the plugin_offline_installer_callback function found in the ~/inc/demo-functions.php.

Published October 11, 2021.

Affected software

Get alerts for Accesspressthemes Access Demo Importer

Reference links