Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion
Metrics
No CVSS v4.0
Attack Vector Network
Attack Complexity Low
Privileges Required None
Scope Unchanged
Confidentiality Impact High
Integrity Impact High
Availability Impact High
User Interaction None
No CVSS v3.0
Access Vector Network
Access Complexity Low
Authentication None
Confidentiality Impact Partial
Integrity Impact Partial
Availability Impact Partial
This CVE is not in the KEV list.
The EPSS score is 0.06685.
Key SSVC decision points have not yet been added.
Affected Vendors & Products
| Vendors | Products |
|---|---|
|
Accesspressthemes
Subscribe
|
Accessbuddy
Subscribe
Accesspress Anonymous Post
Subscribe
Accesspress Basic
Subscribe
Accesspress Custom Css
Subscribe
Accesspress Custom Post Type
Subscribe
Accesspress Ifeeds
Subscribe
Accesspress Lite
Subscribe
Accesspress Mag
Subscribe
Accesspress Parallax
Subscribe
Accesspress Ray
Subscribe
Accesspress Root
Subscribe
Accesspress Social Counter
Subscribe
Accesspress Social Icons
Subscribe
Accesspress Social Login Lite
Subscribe
Accesspress Social Share
Subscribe
Accesspress Staple
Subscribe
Accesspress Store
Subscribe
Agency Lite
Subscribe
Ap Companion
Subscribe
Ap Contact Form
Subscribe
Ap Custom Testimonial
Subscribe
Ap Mega Menu
Subscribe
Ap Pricing Tables Lite
Subscribe
Apex Notification Bar Lite
Subscribe
Aplite
Subscribe
Badge Designer Lite For Woocommerce
Subscribe
Bingle
Subscribe
Bloger
Subscribe
Comments Disable - Accesspress
Subscribe
Construction Lite
Subscribe
Doko
Subscribe
Easy Side Tab
Subscribe
Enlighten
Subscribe
Everest Admin Theme Lite
Subscribe
Everest Coming Soon Lite
Subscribe
Everest Comment Rating Lite
Subscribe
Everest Counter Lite
Subscribe
Everest Faq Manager Lite
Subscribe
Everest Gallery Lite
Subscribe
Everest Gplaces Business Reviews
Subscribe
Everest Review Lite
Subscribe
Everest Tab Lite
Subscribe
Everest Timeline Lite
Subscribe
Fashstore
Subscribe
Form Store To Db
Subscribe
Fotography
Subscribe
Gaga Corp
Subscribe
Gaga Lite
Subscribe
Inline Call To Action Builder Lite
Subscribe
Mcontact Button
Subscribe
One-paze
Subscribe
Parallax Blog
Subscribe
Parallaxsome
Subscribe
Pi Button
Subscribe
Product Slider For Woocommerce Lite
Subscribe
Punte
Subscribe
Revolve
Subscribe
Ripple
Subscribe
Scrollme
Subscribe
Smart Logo Showcase Lite
Subscribe
Smart Scroll Posts
Subscribe
Smart Scroll To Top Lite
Subscribe
Social Auto Poster
Subscribe
Social Review
Subscribe
Sportsmag
Subscribe
Storevilla
Subscribe
Swing Lite
Subscribe
Tauto Poster
Subscribe
The Launcher
Subscribe
The Monday
Subscribe
Total Gdpr Compliance Lite
Subscribe
Total Team Lite
Subscribe
Ultimate-form-builder-lite
Subscribe
Ultimate Author Box Lite
Subscribe
Uncode Lite
Subscribe
Unicon Lite
Subscribe
Vmag
Subscribe
Vmagazine Lite
Subscribe
Vmagazine News
Subscribe
Wp 1 Slider
Subscribe
Wp Blog Manager Lite
Subscribe
Wp Comment Designer Lite
Subscribe
Wp Cookie User Info
Subscribe
Wp Floating Menu
Subscribe
Wp Media Manager Lite
Subscribe
Wp Menu Icons Lite
Subscribe
Wp Popup Banners
Subscribe
Wp Popup Lite
Subscribe
Wp Product Gallery Lite
Subscribe
Wp Tfeed
Subscribe
Zigcy Baby
Subscribe
Zigcy Cosmetics
Subscribe
Zigcy Lite
Subscribe
|
Configuration 1 [-]
|
No data.
No data.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-11779 | Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-08-03T19:49:13.412Z
Reserved: 2021-01-14T00:00:00
Link: CVE-2021-24867
No data.
Status : Modified
Published: 2022-02-21T11:15:08.320
Modified: 2024-11-21T05:53:55.020
Link: CVE-2021-24867
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD