Access Demo Importer <= 1.0.7 - Cross-Site Request Forgery to Data Reset
high
The Access Demo Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.7 due to missing nonce validation on the `adi_demo_data_reset` function called via an AJAX action. This makes it possible for an attacker to reset all data on the site, including posts, pages...
- CVSS:
- 8.1
- Affected:
- up to 1.0.7
- Fixed in:
- 1.0.8
- Disclosed:
- Jan 24, 2022
CVE-2022-23976 on NVD →
AccessPress Themes and Plugin <= Various Versions - Cross-Site Request Forgery
high
A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to cross-site request forgery via the plugin_activation_callback and plugin_deactivate_callback functions, called via AJAX actions, that were missing capability checks and nonce validation. This makes it possible for unauthen...
- CVSS:
- 8.8
- Affected:
- up to 1.0.6
- Fixed in:
- 1.0.7
- Disclosed:
- Jan 11, 2022
AccessPress Themes and Plugin <= Various Versions - Missing Authorization to Arbitrary Plugin Deactivation/Activation
high
A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to unauthorized plugin deactivation and activation via the plugin_activation_callback and plugin_deactivate_callback functions called via AJAX actions that were missing capability checks and nonce validation. This makes it po...
- CVSS:
- 8.8
- Affected:
- up to 1.0.6
- Fixed in:
- 1.0.7
- Disclosed:
- Jan 11, 2022
CVE-2022-23975 on NVD →
AccessPress Themes and Plugin <= Various Versions - Authenticated (Subscriber+) Arbitrary File Upload
high
A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to malicious file uploads via the plugin_offline_installer AJAX action due to a missing capability check in the plugin_offline_installer_callback function found in the /demo-functions.php file or /welcome.php file of the affe...
- CVSS:
- 8.8
- Affected:
- up to 1.0.6
- Fixed in:
- 1.0.7
- Disclosed:
- Oct 6, 2021
CVE-2021-39317 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database