Opstore <= 1.4.5 - Unauthenticated Local File Inclusion
critical
The Opstore theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.4.5. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obt...
- CVSS:
- 9.8
- Affected:
- up to 1.4.5
- Fix:
- No patched version reported
- Disclosed:
- Apr 21, 2025
CVE-2025-39387 on NVD →
AccessPress Themes and Plugin <= Various Versions - Cross-Site Request Forgery
high
A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to cross-site request forgery via the plugin_activation_callback and plugin_deactivate_callback functions, called via AJAX actions, that were missing capability checks and nonce validation. This makes it possible for unauthen...
- CVSS:
- 8.8
- Affected:
- up to 1.4.3
- Fixed in:
- 1.4.4
- Disclosed:
- Jan 11, 2022
AccessPress Themes and Plugin <= Various Versions - Missing Authorization to Arbitrary Plugin Deactivation/Activation
high
A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to unauthorized plugin deactivation and activation via the plugin_activation_callback and plugin_deactivate_callback functions called via AJAX actions that were missing capability checks and nonce validation. This makes it po...
- CVSS:
- 8.8
- Affected:
- up to 1.4.3
- Fixed in:
- 1.4.4
- Disclosed:
- Jan 11, 2022
CVE-2022-23975 on NVD →
AccessPress Themes and Plugin <= Various Versions - Authenticated (Subscriber+) Arbitrary File Upload
high
A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to malicious file uploads via the plugin_offline_installer AJAX action due to a missing capability check in the plugin_offline_installer_callback function found in the /demo-functions.php file or /welcome.php file of the affe...
- CVSS:
- 8.8
- Affected:
- up to 1.4.3
- Fixed in:
- 1.4.4
- Disclosed:
- Oct 6, 2021
CVE-2021-39317 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database