CVE-2021-39317 - CVE House
Back to Database
Status published High CVE-2021-39317

AccessPress Themes - Authenticated Malicious File Upload

Vulnerability Description

A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to malicious file uploads via the plugin_offline_installer AJAX action due to a missing capability check in the plugin_offline_installer_callback function found in the /demo-functions.php file or /welcome.php file of the affected products. The complete list of affected products and their versions are below: WordPress Plugin: AccessPress Demo Importer <=1.0.6 WordPress Themes: accesspress-basic <= 3.2.1 accesspress-lite <= 2.92 accesspress-mag <= 2.6.5 accesspress-parallax <= 4.5 accesspress-root <= 2.5 accesspress-store <= 2.4.9 agency-lite <= 1.1.6 arrival <= 1.4.2 bingle <= 1.0.4 bloger <= 1.2.6 brovy <= 1.3 construction-lite <= 1.2.5 doko <= 1.0.27 edict-lite <= 1.1.4 eightlaw-lite <= 2.1.5 eightmedi-lite <= 2.1.8 eight-sec <= 1.1.4 eightstore-lite <= 1.2.5 enlighten <= 1.3.5 fotography <= 2.4.0 opstore <= 1.4.3 parallaxsome <= 1.3.6 punte <= 1.1.2 revolve <= 1.3.1 ripple <= 1.2.0 sakala <= 1.0.4 scrollme <= 2.1.0 storevilla <= 1.4.1 swing-lite <= 1.1.9 the100 <= 1.1.2 the-launcher <= 1.3.2 the-monday <= 1.4.1 ultra-seven <= 1.2.8 uncode-lite <= 1.3.3 vmag <= 1.2.7 vmagazine-lite <= 1.3.5 vmagazine-news <= 1.0.5 wpparallax <= 2.0.6 wp-store <= 1.1.9 zigcy-baby <= 1.0.6 zigcy-cosmetics <= 1.0.5 zigcy-lite <= 2.0.9

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-39317

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Chloe Chamberland, Wordfence
  • Lenon Leite

Affected Vendor

AccessPress Themes

View all reports →

Affected Software

Access Demo Importer, accesspress-basic, accesspress-lite, accesspress-mag, accesspress-parallax, accesspress-root, accesspress-store, agency-lite, arrival, bingle, bloger, brovy, construction-lite, doko, edict-lite, enlighten, fotography, opstore, parallaxsome, punte, revolve, ripple, sakala, scrollme, storevilla, swing-lite, the100, the-launcher, the-monday, ultra-seven, uncode-lite, vmag, vmagazine-lite, vmagazine-news, wpparallax, wp-store, zigcy-baby, zigcy-cosmetics, zigcy-lite
Vulnerable Versions:
1.0.6, 3.2.1, 2.9.2, 2.6.5, 4.5, 2.5, 2.4.9, 1.1.6, 1.4.2, 1.0.4, 1.2.6, 1.3, 1.2.5, 1.0.27, 1.1.4, 1.3.5, 2.4.0, 1.4.3, 1.3.6, 1.1.2, 1.3.1, 1.2.0, 2.1.0, 1.4.1, 1.1.9, 1.3.2, 1.2.8, 1.3.3, 1.2.7, 1.0.5, 2.0.6, 2.0.9

Timeline

Official Publish: October 11th, 2021
Last Modified: February 14th, 2025
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)