Multiple Themes - Authenticated (Subscriber+) Arbitrary Plugin Activation and Deactivation
high
Several themes are vulnerable to unauthorized access to functionality in various versions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to activate or deactivate arbitrary plugins, which may make arbitrary code execution possible.
- CVSS:
- 8.8
- Affected:
- up to 1.9.1
- Fix:
- No patched version reported
- Disclosed:
- Nov 20, 2024
CVE-2024-52488 on NVD →
AccessPress Themes and Plugin <= Various Versions - Cross-Site Request Forgery
high
A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to cross-site request forgery via the plugin_activation_callback and plugin_deactivate_callback functions, called via AJAX actions, that were missing capability checks and nonce validation. This makes it possible for unauthen...
- CVSS:
- 8.8
- Affected:
- up to 1.9.1
- Fix:
- No patched version reported
- Disclosed:
- Jan 11, 2022
AccessPress Themes and Plugin <= Various Versions - Authenticated (Subscriber+) Arbitrary File Upload
high
A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to malicious file uploads via the plugin_offline_installer AJAX action due to a missing capability check in the plugin_offline_installer_callback function found in the /demo-functions.php file or /welcome.php file of the affe...
- CVSS:
- 8.8
- Affected:
- up to 1.9.1
- Fix:
- No patched version reported
- Disclosed:
- Oct 6, 2021
CVE-2021-39317 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database