Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/9c76bada-fa32-4c2f-9855-d0efd1e63eff | Exploit Third Party Advisory |
https://jetpack.com/2022/01/18/backdoor-found-in-themes-and-plugins-from-accesspress-themes/ | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2022-02-21 03:15
Updated : 2022-03-02 10:03
NVD link : CVE-2021-24867
Mitre link : CVE-2021-24867
JSON object : View
CWE
CWE-912
Hidden Functionality
Products Affected
accesspressthemes
- wp_cookie_user_info
- badge_designer_lite_for_woocommerce
- mcontact_button
- zigcy_cosmetics
- pi_button
- construction_lite
- accessbuddy
- everest_coming_soon_lite
- gaga_corp
- vmagazine_lite
- wp_blog_manager_lite
- wp_tfeed
- accesspress_social_icons
- one-paze
- apex_notification_bar_lite
- social_review
- accesspress_root
- everest_gallery_lite
- smart_logo_showcase_lite
- scrollme
- sportsmag
- accesspress_anonymous_post
- accesspress_ray
- agency_lite
- swing_lite
- social_auto_poster
- wp_1_slider
- gaga_lite
- easy_side_tab
- ultimate-form-builder-lite
- enlighten
- accesspress_store
- everest_counter_lite
- wp_popup_lite
- accesspress_ifeeds
- accesspress_social_login_lite
- parallaxsome
- accesspress_staple
- storevilla
- product_slider_for_woocommerce_lite
- total_team_lite
- uncode_lite
- ap_companion
- zigcy_baby
- accesspress_custom_css
- punte
- wp_menu_icons_lite
- wp_media_manager_lite
- ap_mega_menu
- everest_gplaces_business_reviews
- fotography
- wp_comment_designer_lite
- unicon_lite
- ap_contact_form
- ap_custom_testimonial
- accesspress_social_share
- comments_disable_-_accesspress
- bingle
- everest_review_lite
- everest_comment_rating_lite
- aplite
- wp_popup_banners
- doko
- tauto_poster
- the_launcher
- wp_floating_menu
- vmagazine_news
- accesspress_parallax
- ap_pricing_tables_lite
- bloger
- everest_tab_lite
- smart_scroll_posts
- vmag
- revolve
- everest_admin_theme_lite
- smart_scroll_to_top_lite
- inline_call_to_action_builder_lite
- wp_product_gallery_lite
- fashstore
- parallax_blog
- everest_timeline_lite
- ultimate_author_box_lite
- total_gdpr_compliance_lite
- accesspress_basic
- accesspress_mag
- accesspress_custom_post_type
- everest_faq_manager_lite
- accesspress_social_counter
- zigcy_lite
- the_monday
- accesspress_lite
- form_store_to_db
- ripple