Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion
References
Link | Resource |
---|---|
https://jetpack.com/2022/01/18/backdoor-found-in-themes-and-plugins-from-accesspress-themes/ | Exploit Third Party Advisory |
https://wpscan.com/vulnerability/9c76bada-fa32-4c2f-9855-d0efd1e63eff | Exploit Third Party Advisory |
https://jetpack.com/2022/01/18/backdoor-found-in-themes-and-plugins-from-accesspress-themes/ | Exploit Third Party Advisory |
https://wpscan.com/vulnerability/9c76bada-fa32-4c2f-9855-d0efd1e63eff | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 05:53
Type | Values Removed | Values Added |
---|---|---|
References | () https://jetpack.com/2022/01/18/backdoor-found-in-themes-and-plugins-from-accesspress-themes/ - Exploit, Third Party Advisory | |
References | () https://wpscan.com/vulnerability/9c76bada-fa32-4c2f-9855-d0efd1e63eff - Exploit, Third Party Advisory |
Information
Published : 2022-02-21 11:15
Updated : 2024-11-21 05:53
NVD link : CVE-2021-24867
Mitre link : CVE-2021-24867
CVE.ORG link : CVE-2021-24867
JSON object : View
Products Affected
accesspressthemes
- vmag
- accessbuddy
- product_slider_for_woocommerce_lite
- wp_popup_lite
- accesspress_custom_css
- aplite
- accesspress_social_login_lite
- gaga_lite
- apex_notification_bar_lite
- accesspress_social_share
- the_monday
- wp_media_manager_lite
- zigcy_cosmetics
- parallaxsome
- ap_contact_form
- everest_comment_rating_lite
- ripple
- agency_lite
- accesspress_basic
- vmagazine_news
- the_launcher
- form_store_to_db
- wp_popup_banners
- ap_custom_testimonial
- wp_product_gallery_lite
- badge_designer_lite_for_woocommerce
- swing_lite
- comments_disable_-_accesspress
- punte
- bingle
- mcontact_button
- doko
- one-paze
- ultimate-form-builder-lite
- fotography
- social_review
- accesspress_mag
- total_team_lite
- sportsmag
- accesspress_parallax
- construction_lite
- enlighten
- social_auto_poster
- wp_1_slider
- vmagazine_lite
- accesspress_social_counter
- wp_menu_icons_lite
- tauto_poster
- fashstore
- accesspress_ifeeds
- accesspress_store
- accesspress_custom_post_type
- accesspress_anonymous_post
- accesspress_ray
- zigcy_baby
- wp_blog_manager_lite
- ap_companion
- everest_coming_soon_lite
- wp_cookie_user_info
- zigcy_lite
- smart_logo_showcase_lite
- total_gdpr_compliance_lite
- bloger
- everest_review_lite
- parallax_blog
- revolve
- gaga_corp
- accesspress_lite
- everest_faq_manager_lite
- scrollme
- unicon_lite
- everest_gallery_lite
- accesspress_root
- everest_gplaces_business_reviews
- smart_scroll_posts
- storevilla
- smart_scroll_to_top_lite
- accesspress_social_icons
- everest_tab_lite
- pi_button
- uncode_lite
- ap_pricing_tables_lite
- accesspress_staple
- ap_mega_menu
- wp_floating_menu
- ultimate_author_box_lite
- everest_admin_theme_lite
- wp_tfeed
- wp_comment_designer_lite
- inline_call_to_action_builder_lite
- everest_timeline_lite
- everest_counter_lite
- easy_side_tab
CWE
CWE-912
Hidden Functionality