47
CVE-2021-24867
PoC ×2—CVSS 3.1
9.8 critical
EPSS
19%p97
Published
()
Modified
Description
Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion
- Vendors
- accesspressthemes
- Products
- accessbuddy, accesspress anonymous post, accesspress basic, accesspress custom css, accesspress custom post type, accesspress ifeeds, accesspress lite, accesspress mag, accesspress parallax, accesspress ray, accesspress root, accesspress social counter
- Ecosystems
- WordPress
- Weakness
- CWE-912
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H