High 7.5 Unfixed
2025-04-24≤ 1.4.5
CVE-2025-39387
Minimum safe version
1.4.4
Update to 1.4.4 or later to address 2 fixable vulnerabilities
CVE-2025-39387
CVE-2022-23975
AccessPress Themes and Plugin <= Various Versions - Cross-Site Request Forgery
WordPress Opstore theme <= 1.4.3 - Cross-Site Request Forgery (CSRF) leading to Arbitrary Plugin Activation/Deactivation
WordPress Opstore theme <= 1.4.3 - Authenticated Arbitrary Plugin Activation/Deactivation vulnerability
WordPress Opstore theme <= 1.4.3 - Arbitrary File Upload vulnerability