theme

Arrival Vulnerabilities

10 known security issues reported for the Arrival WordPress theme. Most recent disclosed Apr 24, 2025.

1 critical 3 high

Running Arrival on your site? Check whether your installed version is affected.

Scan your site free

Arrival [arrival] <= 1.4.5 (unfixed)

unknown

[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WPoperation Arrival allows PHP Local File Inclusion. This issue affects Arrival: from n/a through 1.4.5.

Affected:
up to 1.4.5
Fix:
No patched version reported
Disclosed:
Apr 24, 2025

CVE-2025-32921 on NVD →

Arrival <= 1.4.5 - Unauthenticated Local File Inclusion

critical

The Arrival theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.4.5. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obt...

CVSS:
9.8
Affected:
up to 1.4.5
Fix:
No patched version reported
Disclosed:
Apr 21, 2025

CVE-2025-32921 on NVD →

Arrival [arrival] < 1.4.3

unknown

[en] Cross-Site Request Forgery (CSRF) in Access Demo Importer <= 1.0.7 on WordPress allows an attacker to activate any installed plugin.

Affected:
up to 1.4.3
Fixed in:
1.4.3
Disclosed:
Apr 18, 2022

CVE-2022-23975 on NVD →

Arrival [arrival] <= 1.4.2 (unfixed)

unknown

Authenticated Arbitrary Plugin Activation/Deactivation vulnerability discovered by Ex.Mi (Patchstack) in WordPress Arrival theme (versions <= 1.4.2).

Affected:
up to 1.4.2
Fix:
No patched version reported
Disclosed:
Jan 28, 2022

Arrival [arrival] <= 1.4.2 (unfixed)

unknown

Cross-Site Request Forgery (CSRF) leading to Arbitrary Plugin Activation/Deactivation discovered by Ex.Mi (Patchstack) in WordPress Arrival theme (versions <= 1.4.2).

Affected:
up to 1.4.2
Fix:
No patched version reported
Disclosed:
Jan 24, 2022

AccessPress Themes and Plugin <= Various Versions - Cross-Site Request Forgery

high

A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to cross-site request forgery via the plugin_activation_callback and plugin_deactivate_callback functions, called via AJAX actions, that were missing capability checks and nonce validation. This makes it possible for unauthen...

CVSS:
8.8
Affected:
up to 1.4.2
Fixed in:
1.4.3
Disclosed:
Jan 11, 2022

AccessPress Themes and Plugin <= Various Versions - Missing Authorization to Arbitrary Plugin Deactivation/Activation

high

A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to unauthorized plugin deactivation and activation via the plugin_activation_callback and plugin_deactivate_callback functions called via AJAX actions that were missing capability checks and nonce validation. This makes it po...

CVSS:
8.8
Affected:
up to 1.4.2
Fixed in:
1.4.3
Disclosed:
Jan 11, 2022

CVE-2022-23975 on NVD →

Arrival [arrival] < 1.4.3

unknown

A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to cross-site request forgery via the plugin_activation_callback and plugin_deactivate_callback functions, called via AJAX actions, that were missing capability checks and nonce validation. This makes it possible for unauthen...

Affected:
up to 1.4.3
Fixed in:
1.4.3
Disclosed:
Jan 11, 2022

Arrival [arrival] <= 1.4.2

unknown

[en] A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to malicious file uploads via the plugin_offline_installer AJAX action due to a missing capability check in the plugin_offline_installer_callback function found in the /demo-functions.php file or /welcome.php file of the...

Affected:
up to 1.4.2
Fixed in:
1.4.2
Disclosed:
Oct 11, 2021

CVE-2021-39317 on NVD →

AccessPress Themes and Plugin <= Various Versions - Authenticated (Subscriber+) Arbitrary File Upload

high

A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to malicious file uploads via the plugin_offline_installer AJAX action due to a missing capability check in the plugin_offline_installer_callback function found in the /demo-functions.php file or /welcome.php file of the affe...

CVSS:
8.8
Affected:
up to 1.4.2
Fixed in:
1.4.3
Disclosed:
Oct 6, 2021

CVE-2021-39317 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database