Vulnerability Details CVE-2021-24867
Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion
Exploit prediction scoring system (EPSS) score
EPSS Score 0.064
EPSS Ranking 90.6%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2021-24867
-
cpe:2.3:a:accesspressthemes:accessbuddy:1.0.0
-
cpe:2.3:a:accesspressthemes:accesspress_anonymous_post:2.8.0
-
cpe:2.3:a:accesspressthemes:accesspress_basic:3.2.1
-
cpe:2.3:a:accesspressthemes:accesspress_custom_css:2.0.1
-
cpe:2.3:a:accesspressthemes:accesspress_custom_post_type:1.0.8
-
cpe:2.3:a:accesspressthemes:accesspress_ifeeds:4.0.3
-
cpe:2.3:a:accesspressthemes:accesspress_lite:2.92
-
cpe:2.3:a:accesspressthemes:accesspress_mag:2.6.5
-
cpe:2.3:a:accesspressthemes:accesspress_parallax:4.5
-
cpe:2.3:a:accesspressthemes:accesspress_ray:1.19.5
-
cpe:2.3:a:accesspressthemes:accesspress_root:2.5
-
cpe:2.3:a:accesspressthemes:accesspress_social_counter:1.9.1
-
cpe:2.3:a:accesspressthemes:accesspress_social_icons:1.8.2
-
cpe:2.3:a:accesspressthemes:accesspress_social_login_lite:3.4.7
-
cpe:2.3:a:accesspressthemes:accesspress_social_share:4.5.5
-
cpe:2.3:a:accesspressthemes:accesspress_staple:1.9.1
-
cpe:2.3:a:accesspressthemes:accesspress_store:2.4.9
-
cpe:2.3:a:accesspressthemes:agency_lite:1.1.6
-
cpe:2.3:a:accesspressthemes:ap_companion:*
-
cpe:2.3:a:accesspressthemes:ap_contact_form:1.0.6
-
cpe:2.3:a:accesspressthemes:ap_custom_testimonial:1.4.6
-
cpe:2.3:a:accesspressthemes:ap_mega_menu:3.0.5
-
cpe:2.3:a:accesspressthemes:ap_pricing_tables_lite:1.1.2
-
cpe:2.3:a:accesspressthemes:apex_notification_bar_lite:2.0.4
-
cpe:2.3:a:accesspressthemes:aplite:1.0.6
-
cpe:2.3:a:accesspressthemes:badge_designer_lite_for_woocommerce:1.1.0
-
cpe:2.3:a:accesspressthemes:bingle:1.0.4
-
cpe:2.3:a:accesspressthemes:bloger:1.2.6
-
cpe:2.3:a:accesspressthemes:comments_disable_-_accesspress:1.0.7
-
cpe:2.3:a:accesspressthemes:construction_lite:1.2.5
-
cpe:2.3:a:accesspressthemes:doko:1.0.27
-
cpe:2.3:a:accesspressthemes:easy_side_tab:1.0.7
-
cpe:2.3:a:accesspressthemes:enlighten:1.3.5
-
cpe:2.3:a:accesspressthemes:everest_admin_theme_lite:1.0.7
-
cpe:2.3:a:accesspressthemes:everest_coming_soon_lite:1.1.0
-
cpe:2.3:a:accesspressthemes:everest_comment_rating_lite:2.0.4
-
cpe:2.3:a:accesspressthemes:everest_counter_lite:2.0.7
-
cpe:2.3:a:accesspressthemes:everest_faq_manager_lite:1.0.8
-
cpe:2.3:a:accesspressthemes:everest_gallery_lite:1.0.8
-
cpe:2.3:a:accesspressthemes:everest_gplaces_business_reviews:1.0.9
-
cpe:2.3:a:accesspressthemes:everest_review_lite:1.0.7
-
cpe:2.3:a:accesspressthemes:everest_tab_lite:2.0.3
-
cpe:2.3:a:accesspressthemes:everest_timeline_lite:1.1.1
-
cpe:2.3:a:accesspressthemes:fashstore:1.2.1
-
cpe:2.3:a:accesspressthemes:form_store_to_db:1.0.9
-
cpe:2.3:a:accesspressthemes:fotography:2.4.0
-
cpe:2.3:a:accesspressthemes:gaga_corp:1.0.8
-
cpe:2.3:a:accesspressthemes:gaga_lite:1.4.2
-
cpe:2.3:a:accesspressthemes:inline_call_to_action_builder_lite:1.1.0
-
cpe:2.3:a:accesspressthemes:mcontact_button:*
-
cpe:2.3:a:accesspressthemes:one-paze:2.2.8
-
cpe:2.3:a:accesspressthemes:parallax_blog:3.1.1574941215
-
cpe:2.3:a:accesspressthemes:parallaxsome:1.3.6
-
cpe:2.3:a:accesspressthemes:pi_button:3.3.3
-
cpe:2.3:a:accesspressthemes:product_slider_for_woocommerce_lite:1.1.5
-
cpe:2.3:a:accesspressthemes:punte:1.1.2
-
cpe:2.3:a:accesspressthemes:revolve:1.3.1
-
cpe:2.3:a:accesspressthemes:ripple:1.2.0
-
cpe:2.3:a:accesspressthemes:scrollme:2.1.0
-
cpe:2.3:a:accesspressthemes:smart_logo_showcase_lite:1.1.7
-
cpe:2.3:a:accesspressthemes:smart_scroll_posts:2.0.8
-
cpe:2.3:a:accesspressthemes:smart_scroll_to_top_lite:1.0.3
-
cpe:2.3:a:accesspressthemes:social_auto_poster:2.1.3
-
cpe:2.3:a:accesspressthemes:social_review:*
-
cpe:2.3:a:accesspressthemes:sportsmag:1.2.1
-
cpe:2.3:a:accesspressthemes:storevilla:1.4.1
-
cpe:2.3:a:accesspressthemes:swing_lite:1.1.9
-
cpe:2.3:a:accesspressthemes:tauto_poster:1.4.5
-
cpe:2.3:a:accesspressthemes:the_launcher:1.3.2
-
cpe:2.3:a:accesspressthemes:the_monday:1.4.1
-
cpe:2.3:a:accesspressthemes:total_gdpr_compliance_lite:1.0.4
-
cpe:2.3:a:accesspressthemes:total_team_lite:1.1.1
-
cpe:2.3:a:accesspressthemes:ultimate-form-builder-lite:1.5.0
-
cpe:2.3:a:accesspressthemes:ultimate_author_box_lite:1.1.2
-
cpe:2.3:a:accesspressthemes:uncode_lite:1.3.1
-
cpe:2.3:a:accesspressthemes:unicon_lite:1.2.6
-
cpe:2.3:a:accesspressthemes:vmag:1.2.7
-
cpe:2.3:a:accesspressthemes:vmagazine_lite:1.3.5
-
cpe:2.3:a:accesspressthemes:vmagazine_news:1.0.5
-
cpe:2.3:a:accesspressthemes:wp_1_slider:1.2.9
-
cpe:2.3:a:accesspressthemes:wp_blog_manager_lite:1.1.0
-
cpe:2.3:a:accesspressthemes:wp_comment_designer_lite:2.0.3
-
cpe:2.3:a:accesspressthemes:wp_cookie_user_info:1.0.7
-
cpe:2.3:a:accesspressthemes:wp_floating_menu:1.4.4
-
cpe:2.3:a:accesspressthemes:wp_media_manager_lite:1.1.2
-
cpe:2.3:a:accesspressthemes:wp_menu_icons_lite:*
-
cpe:2.3:a:accesspressthemes:wp_popup_banners:1.2.3
-
cpe:2.3:a:accesspressthemes:wp_popup_lite:1.0.8
-
cpe:2.3:a:accesspressthemes:wp_product_gallery_lite:1.1.1
-
cpe:2.3:a:accesspressthemes:wp_tfeed:1.6.7
-
cpe:2.3:a:accesspressthemes:zigcy_baby:1.0.6
-
cpe:2.3:a:accesspressthemes:zigcy_cosmetics:1.0.5
-
cpe:2.3:a:accesspressthemes:zigcy_lite:2.0.9