CVE-2021-39317 describes a critical vulnerability in the AccessPress Demo Importer WordPress plugin (<=1.0.6) and numerous AccessPress Themes, allowing unauthenticated attackers to upload malicious files. This flaw stems from a missing capability check in the plugin_offline_installer AJAX action within the /demo-functions.php or /welcome.php files. Rated with a CVSS score of 8.8 (High), the vulnerability has a network attack vector and low attack complexity, enabling unauthorized users to achieve high confidentiality, integrity, and availability impacts. The EPSS score of 0.014 indicates a low probability of exploitation in the wild. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting a lack of widespread attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.7CPE matchmatch criteria | cpe:2.3:a:accesspressthemes:access_demo_importer:*:*:*:*:*:wordpress:*:* | ||
<= 2.92CPE matchmatch criteria | cpe:2.3:a:accesspressthemes:accesspress-lite:*:*:*:*:*:wordpress:*:* | ||
<= 2.6.5CPE matchmatch criteria | cpe:2.3:a:accesspressthemes:accesspress-mag:*:*:*:*:*:wordpress:*:* | ||
<= 4.5CPE matchmatch criteria | cpe:2.3:a:accesspressthemes:accesspress-parallax:*:*:*:*:*:wordpress:*:* | ||
<= 2.5CPE matchmatch criteria | cpe:2.3:a:accesspressthemes:accesspress-root:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.