CVE-2021-39317

Public Exploit
AccessPress Themes - Authenticated Malicious File Upload

Description

A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to malicious file uploads via the plugin_offline_installer AJAX action due to a missing capability check in the plugin_offline_installer_callback function found in the /demo-functions.php file or /welcome.php file of the affected products. The complete list of affected products and their versions are below: WordPress Plugin: AccessPress Demo Importer <=1.0.6 WordPress Themes: accesspress-basic <= 3.2.1 accesspress-lite <= 2.92 accesspress-mag <= 2.6.5 accesspress-parallax <= 4.5 accesspress-root <= 2.5 accesspress-store <= 2.4.9 agency-lite <= 1.1.6 arrival <= 1.4.2 bingle <= 1.0.4 bloger <= 1.2.6 brovy <= 1.3 construction-lite <= 1.2.5 doko <= 1.0.27 edict-lite <= 1.1.4 eightlaw-lite <= 2.1.5 eightmedi-lite <= 2.1.8 eight-sec <= 1.1.4 eightstore-lite <= 1.2.5 enlighten <= 1.3.5 fotography <= 2.4.0 opstore <= 1.4.3 parallaxsome <= 1.3.6 punte <= 1.1.2 revolve <= 1.3.1 ripple <= 1.2.0 sakala <= 1.0.4 scrollme <= 2.1.0 storevilla <= 1.4.1 swing-lite <= 1.1.9 the100 <= 1.1.2 the-launcher <= 1.3.2 the-monday <= 1.4.1 ultra-seven <= 1.2.8 uncode-lite <= 1.3.3 vmag <= 1.2.7 vmagazine-lite <= 1.3.5 vmagazine-news <= 1.0.5 wpparallax <= 2.0.6 wp-store <= 1.1.9 zigcy-baby <= 1.0.6 zigcy-cosmetics <= 1.0.5 zigcy-lite <= 2.0.9

Remediation

Solution:

  • Update to the latest available version of software for each, or uninstall from WordPress site if no updated software available.

Categories

8.8
CVSS
Severity: High
CVSS 3.1 •
CVSS 2.0 •
EPSS 0.65%
Third-Party Advisory patchstack.com Third-Party Advisory wordpress.org Third-Party Advisory wordpress.org Third-Party Advisory wordfence.com
Affected: AccessPress Themes Access Demo Importer
Affected: AccessPress Themes accesspress-basic
Affected: AccessPress Themes accesspress-lite
Affected: AccessPress Themes accesspress-mag
Affected: AccessPress Themes accesspress-parallax
Affected: AccessPress Themes accesspress-root
Affected: AccessPress Themes accesspress-store
Affected: AccessPress Themes agency-lite
Affected: AccessPress Themes arrival
Affected: AccessPress Themes bingle
Affected: AccessPress Themes bloger
Affected: AccessPress Themes brovy
Affected: AccessPress Themes construction-lite
Affected: AccessPress Themes doko
Affected: AccessPress Themes edict-lite
Affected: AccessPress Themes enlighten
Affected: AccessPress Themes fotography
Affected: AccessPress Themes opstore
Affected: AccessPress Themes parallaxsome
Affected: AccessPress Themes punte
Affected: AccessPress Themes revolve
Affected: AccessPress Themes ripple
Affected: AccessPress Themes sakala
Affected: AccessPress Themes scrollme
Affected: AccessPress Themes storevilla
Affected: AccessPress Themes swing-lite
Affected: AccessPress Themes swing-lite
Affected: AccessPress Themes the100
Affected: AccessPress Themes the-launcher
Affected: AccessPress Themes the-monday
Affected: AccessPress Themes ultra-seven
Affected: AccessPress Themes uncode-lite
Affected: AccessPress Themes vmag
Affected: AccessPress Themes vmagazine-lite
Affected: AccessPress Themes vmagazine-news
Affected: AccessPress Themes wpparallax
Affected: AccessPress Themes wp-store
Affected: AccessPress Themes zigcy-baby
Affected: AccessPress Themes zigcy-cosmetics
Affected: AccessPress Themes zigcy-lite
Published at:
Updated at:

References

Frequently Asked Questions

What is the severity of CVE-2021-39317?
CVE-2021-39317 has been scored as a high severity vulnerability.
How to fix CVE-2021-39317?
To fix CVE-2021-39317: Update to the latest available version of software for each, or uninstall from WordPress site if no updated software available.
Is CVE-2021-39317 being actively exploited in the wild?
It is possible that CVE-2021-39317 is being exploited or will be exploited in a near future based on public information. According to its EPSS score, there is a ~1% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
What software or system is affected by CVE-2021-39317?
CVE-2021-39317 affects AccessPress Themes Access Demo Importer, AccessPress Themes accesspress-basic, AccessPress Themes accesspress-lite, AccessPress Themes accesspress-mag, AccessPress Themes accesspress-parallax, AccessPress Themes accesspress-root, AccessPress Themes accesspress-store, AccessPress Themes agency-lite, AccessPress Themes arrival, AccessPress Themes bingle, AccessPress Themes bloger, AccessPress Themes brovy, AccessPress Themes construction-lite, AccessPress Themes doko, AccessPress Themes edict-lite, AccessPress Themes enlighten, AccessPress Themes fotography, AccessPress Themes opstore, AccessPress Themes parallaxsome, AccessPress Themes punte, AccessPress Themes revolve, AccessPress Themes ripple, AccessPress Themes sakala, AccessPress Themes scrollme, AccessPress Themes storevilla, AccessPress Themes swing-lite, AccessPress Themes swing-lite, AccessPress Themes the100, AccessPress Themes the-launcher, AccessPress Themes the-monday, AccessPress Themes ultra-seven, AccessPress Themes uncode-lite, AccessPress Themes vmag, AccessPress Themes vmagazine-lite, AccessPress Themes vmagazine-news, AccessPress Themes wpparallax, AccessPress Themes wp-store, AccessPress Themes zigcy-baby, AccessPress Themes zigcy-cosmetics, AccessPress Themes zigcy-lite.
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.