Arrival [arrival] <= 1.4.5 (unfixed)
unknown
[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WPoperation Arrival allows PHP Local File Inclusion. This issue affects Arrival: from n/a through 1.4.5.
- Affected:
- up to 1.4.5
- Fix:
- No patched version reported
- Disclosed:
- Apr 24, 2025
CVE-2025-32921 on NVD →
Arrival <= 1.4.5 - Unauthenticated Local File Inclusion
critical
The Arrival theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.4.5. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obt...
- CVSS:
- 9.8
- Affected:
- up to 1.4.5
- Fix:
- No patched version reported
- Disclosed:
- Apr 21, 2025
CVE-2025-32921 on NVD →
Arrival [arrival] < 1.4.3
unknown
[en] Cross-Site Request Forgery (CSRF) in Access Demo Importer <= 1.0.7 on WordPress allows an attacker to activate any installed plugin.
- Affected:
- up to 1.4.3
- Fixed in:
- 1.4.3
- Disclosed:
- Apr 18, 2022
CVE-2022-23975 on NVD →
Arrival [arrival] <= 1.4.2 (unfixed)
unknown
Authenticated Arbitrary Plugin Activation/Deactivation vulnerability discovered by Ex.Mi (Patchstack) in WordPress Arrival theme (versions <= 1.4.2).
- Affected:
- up to 1.4.2
- Fix:
- No patched version reported
- Disclosed:
- Jan 28, 2022
Arrival [arrival] <= 1.4.2 (unfixed)
unknown
Cross-Site Request Forgery (CSRF) leading to Arbitrary Plugin Activation/Deactivation discovered by Ex.Mi (Patchstack) in WordPress Arrival theme (versions <= 1.4.2).
- Affected:
- up to 1.4.2
- Fix:
- No patched version reported
- Disclosed:
- Jan 24, 2022
AccessPress Themes and Plugin <= Various Versions - Cross-Site Request Forgery
high
A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to cross-site request forgery via the plugin_activation_callback and plugin_deactivate_callback functions, called via AJAX actions, that were missing capability checks and nonce validation. This makes it possible for unauthen...
- CVSS:
- 8.8
- Affected:
- up to 1.4.2
- Fixed in:
- 1.4.3
- Disclosed:
- Jan 11, 2022
AccessPress Themes and Plugin <= Various Versions - Missing Authorization to Arbitrary Plugin Deactivation/Activation
high
A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to unauthorized plugin deactivation and activation via the plugin_activation_callback and plugin_deactivate_callback functions called via AJAX actions that were missing capability checks and nonce validation. This makes it po...
- CVSS:
- 8.8
- Affected:
- up to 1.4.2
- Fixed in:
- 1.4.3
- Disclosed:
- Jan 11, 2022
CVE-2022-23975 on NVD →
Arrival [arrival] < 1.4.3
unknown
A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to cross-site request forgery via the plugin_activation_callback and plugin_deactivate_callback functions, called via AJAX actions, that were missing capability checks and nonce validation. This makes it possible for unauthen...
- Affected:
- up to 1.4.3
- Fixed in:
- 1.4.3
- Disclosed:
- Jan 11, 2022
Arrival [arrival] <= 1.4.2
unknown
[en] A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to malicious file uploads via the plugin_offline_installer AJAX action due to a missing capability check in the plugin_offline_installer_callback function found in the /demo-functions.php file or /welcome.php file of the...
- Affected:
- up to 1.4.2
- Fixed in:
- 1.4.2
- Disclosed:
- Oct 11, 2021
CVE-2021-39317 on NVD →
AccessPress Themes and Plugin <= Various Versions - Authenticated (Subscriber+) Arbitrary File Upload
high
A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to malicious file uploads via the plugin_offline_installer AJAX action due to a missing capability check in the plugin_offline_installer_callback function found in the /demo-functions.php file or /welcome.php file of the affe...
- CVSS:
- 8.8
- Affected:
- up to 1.4.2
- Fixed in:
- 1.4.3
- Disclosed:
- Oct 6, 2021
CVE-2021-39317 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database