CVE-2021-39317: AccessPress Themes - Authenticated Malicious File Upload
A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to malicious file uploads via the pluginofflineinstaller AJAX action due to a missing capability check in the pluginofflineinstallercallback function found in the /demo-functions.php file or /welcome.php file of the affected products. The complete list of affected products and their versions are below: WordPress Plugin: AccessPress Demo Importer <=1.0.6 WordPress Themes: accesspress-basic <= 3.2.1 accesspress-lite <= 2.92 accesspress-mag <= 2.6.5 accesspress-parallax <= 4.5 accesspress-root <= 2.5 accesspress-store <= 2.4.9 agency-lite <= 1.1.6 arrival <= 1.4.2 bingle <= 1.0.4 bloger <= 1.2.6 brovy <= 1.3 construction-lite <= 1.2.5 doko <= 1.0.27 edict-lite <= 1.1.4 eightlaw-lite <= 2.1.5 eightmedi-lite <= 2.1.8 eight-sec <= 1.1.4 eightstore-lite <= 1.2.5 enlighten <= 1.3.5 fotography <= 2.4.0 opstore <= 1.4.3 parallaxsome <= 1.3.6 punte <= 1.1.2 revolve <= 1.3.1 ripple <= 1.2.0 sakala <= 1.0.4 scrollme <= 2.1.0 storevilla <= 1.4.1 swing-lite <= 1.1.9 the100 <= 1.1.2 the-launcher <= 1.3.2 the-monday <= 1.4.1 ultra-seven <= 1.2.8 uncode-lite <= 1.3.3 vmag <= 1.2.7 vmagazine-lite <= 1.3.5 vmagazine-news <= 1.0.5 wpparallax <= 2.0.6 wp-store <= 1.1.9 zigcy-baby <= 1.0.6 zigcy-cosmetics <= 1.0.5 zigcy-lite <= 2.0.9
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress plugin: AccessPress Demo Importerto a version that resolves this vulnerability.Fixed in <=1.0.6 - Upgrade
Upgrade
wordpress theme: accesspress-basicto a version that resolves this vulnerability.Fixed in <= 3.2.1 - Upgrade
Upgrade
wordpress theme: accesspress-liteto a version that resolves this vulnerability.Fixed in <= 2.92 - Upgrade
Upgrade
wordpress theme: accesspress-magto a version that resolves this vulnerability.Fixed in <= 2.6.5 - Upgrade
Upgrade
wordpress theme: accesspress-parallaxto a version that resolves this vulnerability.Fixed in <= 4.5 - Upgrade
Upgrade
wordpress theme: accesspress-rootto a version that resolves this vulnerability.Fixed in <= 2.5 - Upgrade
Upgrade
wordpress theme: accesspress-storeto a version that resolves this vulnerability.Fixed in <= 2.4.9 - Upgrade
Upgrade
wordpress theme: agency-liteto a version that resolves this vulnerability.Fixed in <= 1.1.6 - Upgrade
Upgrade
wordpress theme: arrivalto a version that resolves this vulnerability.Fixed in <= 1.4.2 - Upgrade
Upgrade
wordpress theme: bingleto a version that resolves this vulnerability.Fixed in <= 1.0.4 - Upgrade
Upgrade
wordpress theme: blogerto a version that resolves this vulnerability.Fixed in <= 1.2.6 - Upgrade
Upgrade
wordpress theme: brovyto a version that resolves this vulnerability.Fixed in <= 1.3 - Upgrade
Upgrade
wordpress theme: construction-liteto a version that resolves this vulnerability.Fixed in <= 1.2.5 - Upgrade
Upgrade
wordpress theme: dokoto a version that resolves this vulnerability.Fixed in <= 1.0.27 - Upgrade
Upgrade
wordpress theme: edict-liteto a version that resolves this vulnerability.Fixed in <= 1.1.4 - Upgrade
Upgrade
wordpress theme: eightlaw-liteto a version that resolves this vulnerability.Fixed in <= 2.1.5 - Upgrade
Upgrade
wordpress theme: eightmedi-liteto a version that resolves this vulnerability.Fixed in <= 2.1.8 - Upgrade
Upgrade
wordpress theme: eight-secto a version that resolves this vulnerability.Fixed in <= 1.1.4 - Upgrade
Upgrade
wordpress theme: eightstore-liteto a version that resolves this vulnerability.Fixed in <= 1.2.5 - Upgrade
Upgrade
wordpress theme: enlightento a version that resolves this vulnerability.Fixed in <= 1.3.5 - Upgrade
Upgrade
wordpress theme: fotographyto a version that resolves this vulnerability.Fixed in <= 2.4.0 - Upgrade
Upgrade
wordpress theme: opstoreto a version that resolves this vulnerability.Fixed in <= 1.4.3 - Upgrade
Upgrade
wordpress theme: parallaxsometo a version that resolves this vulnerability.Fixed in <= 1.3.6 - Upgrade
Upgrade
wordpress theme: punteto a version that resolves this vulnerability.Fixed in <= 1.1.2 - Upgrade
Upgrade
wordpress theme: revolveto a version that resolves this vulnerability.Fixed in <= 1.3.1 - Upgrade
Upgrade
wordpress theme: rippleto a version that resolves this vulnerability.Fixed in <= 1.2.0 - Upgrade
Upgrade
wordpress theme: sakalato a version that resolves this vulnerability.Fixed in <= 1.0.4 - Upgrade
Upgrade
wordpress theme: scrollmeto a version that resolves this vulnerability.Fixed in <= 2.1.0 - Upgrade
Upgrade
wordpress theme: storevillato a version that resolves this vulnerability.Fixed in <= 1.4.1 - Upgrade
Upgrade
wordpress theme: swing-liteto a version that resolves this vulnerability.Fixed in <= 1.1.9 - Upgrade
Upgrade
wordpress theme: the100to a version that resolves this vulnerability.Fixed in <= 1.1.2 - Upgrade
Upgrade
wordpress theme: the-launcherto a version that resolves this vulnerability.Fixed in <= 1.3.2 - Upgrade
Upgrade
wordpress theme: the-mondayto a version that resolves this vulnerability.Fixed in <= 1.4.1 - Upgrade
Upgrade
wordpress theme: ultra-sevento a version that resolves this vulnerability.Fixed in <= 1.2.8 - Upgrade
Upgrade
wordpress theme: uncode-liteto a version that resolves this vulnerability.Fixed in <= 1.3.3 - Upgrade
Upgrade
wordpress theme: vmagto a version that resolves this vulnerability.Fixed in <= 1.2.7 - Upgrade
Upgrade
wordpress theme: vmagazine-liteto a version that resolves this vulnerability.Fixed in <= 1.3.5 - Upgrade
Upgrade
wordpress theme: vmagazine-newsto a version that resolves this vulnerability.Fixed in <= 1.0.5 - Upgrade
Upgrade
wordpress theme: wpparallaxto a version that resolves this vulnerability.Fixed in <= 2.0.6 - Upgrade
Upgrade
wordpress theme: wp-storeto a version that resolves this vulnerability.Fixed in <= 1.1.9 - Upgrade
Upgrade
wordpress theme: zigcy-babyto a version that resolves this vulnerability.Fixed in <= 1.0.6 - Upgrade
Upgrade
wordpress theme: zigcy-cosmeticsto a version that resolves this vulnerability.Fixed in <= 1.0.5 - Upgrade
Upgrade
wordpress theme: zigcy-liteto a version that resolves this vulnerability.Fixed in <= 2.0.9
Event History
Frequently Asked Questions
What is CVE-2021-39317?
CVE-2021-39317 is a vulnerability in a WordPress plugin and several WordPress themes developed by AccessPress Themes that allows for malicious file uploads.
What is the severity of CVE-2021-39317?
The severity of CVE-2021-39317 is high with a CVSS score of 8.8.
Which software is affected by CVE-2021-39317?
The following software is affected by CVE-2021-39317: Access Demo Importer (up to version 1.0.7), Accesspress-lite (up to version 2.92), Accesspress-mag (up to version 2.6.5), Accesspress-parallax (up to version 4.5), Accesspress-root (up to version 2.5), Accesspress-store (up to version 2.4.9), Accesspress Basic (up to version 3.2.1), Agency-lite (up to version 1.1.6), Arrival (up to version 1.4.2), Bingle (up to version 1.0.4), Bloger (up to version 1.2.6), Brovy (up to version 1.3), Construction-lite (up to version 1.2.5), Doko (up to version 1.0.27), Edict-lite (up to version 1.1.4), Eight-sec (up to version 1.1.4), Eightlaw-lite (up to version 2.1.5), Eightmedi-lite (up to version 2.1.8), Eightstore-lite (up to version 1.2.5), Enlighten (up to version 1.3.5), Fotography (up to version 2.4.0), Opstore (up to version 1.4.3), Parallaxsome (up to version 1.3.6), Punte (up to version 1.1.2), Revolve (up to version 1.3.1), Ripple (up to version 1.2.0), Sakala (up to version 1.0.4), Scrollme (up to version 2.1.0), Storevilla (up to version 1.4.1), Swing-lite (up to version 1.1.9), The-launcher (up to version 1.3.2), The-monday (up to version 1.4.1), The100 (up to version 1.1.2), Ultra-seven (up to version 1.2.8), Uncode-lite (up to version 1.3.3), Vmag (up to version 1.2.7), Vmagazine-lite (up to version 1.3.5), Vmagazine-news (up to version 1.0.5), Wp-store (up to version 1.1.9), Wpparallax (up to version 2.0.6), Zigcy-baby (up to version 1.0.6), Zigcy-cosmetics (up to version 1.0.5), Zigcy-lite (up to version 2.0.9).
How do I fix CVE-2021-39317?
To fix CVE-2021-39317, update the affected plugin and themes to the latest version provided by AccessPress Themes.
Do I need to take any other actions to mitigate CVE-2021-39317?
In addition to updating the affected software, it is recommended to only install plugins and themes from trusted sources, regularly monitor for vulnerability updates, and implement web application firewalls.