accesspressthemes Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with accesspressthemes products.
Products
- access_demo_importer1 vulnerability
- AccessPress Social Icons1 vulnerability
- ultimate-form-builder-lite1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2021-47910MEDIUM | WordPress Plugin AccessPress Social Icons 1.8.2 Stored XSSAccessPress Social Icons 1.8.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by entering JavaScript payloads into the 'icon title' field. Attackers can store XSS payloads like image tags with onerror event handlers that execute when the plugin page is viewed, affecting all users who access the plugin interface. CWE-79May 10, 2026 | CVSS5.1v4.0 | EPSS0.239% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-39317HIGH | AccessPress Themes - Authenticated Malicious File UploadA WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to malicious file uploads via the plugin_offline_installer AJAX action due to a missing capability check in the plugin_offline_installer_callback function found in the /demo-functions.php file or /welcome.php file of the affected products. The complete list of affected products and their versions are below: WordPress Plugin: AccessPress Demo Importer <=1.0.6 WordPress Themes: accesspress-basic <= 3.2.1… | CVSS8.8v3.1 | EPSS1.71% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-15919CRITICAL | accesspressthemes ultimate-form-builder-lite Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')The ultimate-form-builder-lite plugin before 1.3.7 for WordPress has SQL Injection, with resultant PHP Object Injection, via wp-admin/admin-ajax.php. CWE-89Oct 26, 2017 | CVSS9.8v3.0 | EPSS2.48% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |