9.8

CVE-2021-24867

Exploit

Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion

Data is provided by the National Vulnerability Database (NVD)
AccesspressthemesAccessbuddy Version1.0.0 SwPlatformwordpress
AccesspressthemesAccesspress Anonymous Post Version2.8.0 SwPlatformwordpress
AccesspressthemesAccesspress Basic Version3.2.1 SwPlatformwordpress
AccesspressthemesAccesspress Custom Css Version2.0.1 SwPlatformwordpress
AccesspressthemesAccesspress Custom Post Type Version1.0.8 SwPlatformwordpress
AccesspressthemesAccesspress Ifeeds Version4.0.3 SwPlatformwordpress
AccesspressthemesAccesspress Lite Version2.92 SwPlatformwordpress
AccesspressthemesAccesspress Mag Version2.6.5 SwPlatformwordpress
AccesspressthemesAccesspress Parallax Version4.5 SwPlatformwordpress
AccesspressthemesAccesspress Ray Version1.19.5 SwPlatformwordpress
AccesspressthemesAccesspress Root Version2.5 SwPlatformwordpress
AccesspressthemesAccesspress Social Counter Version1.9.1 SwPlatformwordpress
AccesspressthemesAccesspress Social Icons Version1.8.2 SwPlatformwordpress
AccesspressthemesAccesspress Social Login Lite Version3.4.7 SwPlatformwordpress
AccesspressthemesAccesspress Social Share Version4.5.5 SwPlatformwordpress
AccesspressthemesAccesspress Staple Version1.9.1 SwPlatformwordpress
AccesspressthemesAccesspress Store Version2.4.9 SwPlatformwordpress
AccesspressthemesAgency Lite Version1.1.6 SwPlatformwordpress
AccesspressthemesAp Companion SwPlatformwordpress Version < 1.0.7
AccesspressthemesAp Contact Form Version1.0.6 SwPlatformwordpress
AccesspressthemesAp Custom Testimonial Version1.4.6 SwPlatformwordpress
AccesspressthemesAp Mega Menu Version3.0.5 SwPlatformwordpress
AccesspressthemesAp Pricing Tables Lite Version1.1.2 SwPlatformwordpress
AccesspressthemesApex Notification Bar Lite Version2.0.4 SwPlatformwordpress
AccesspressthemesAplite Version1.0.6 SwPlatformwordpress
AccesspressthemesBadge Designer Lite For Woocommerce Version1.1.0 SwPlatformwordpress
AccesspressthemesBingle Version1.0.4 SwPlatformwordpress
AccesspressthemesBloger Version1.2.6 SwPlatformwordpress
AccesspressthemesComments Disable - Accesspress Version1.0.7 SwPlatformwordpress
AccesspressthemesConstruction Lite Version1.2.5 SwPlatformwordpress
AccesspressthemesDoko Version1.0.27 SwPlatformwordpress
AccesspressthemesEasy Side Tab Version1.0.7 SwPlatformwordpress
AccesspressthemesEnlighten Version1.3.5 SwPlatformwordpress
AccesspressthemesEverest Admin Theme Lite Version1.0.7 SwPlatformwordpress
AccesspressthemesEverest Coming Soon Lite Version1.1.0 SwPlatformwordpress
AccesspressthemesEverest Comment Rating Lite Version2.0.4 SwPlatformwordpress
AccesspressthemesEverest Counter Lite Version2.0.7 SwPlatformwordpress
AccesspressthemesEverest Faq Manager Lite Version1.0.8 SwPlatformwordpress
AccesspressthemesEverest Gallery Lite Version1.0.8 SwPlatformwordpress
AccesspressthemesEverest Gplaces Business Reviews Version1.0.9 SwPlatformwordpress
AccesspressthemesEverest Review Lite Version1.0.7 SwPlatformwordpress
AccesspressthemesEverest Tab Lite Version2.0.3 SwPlatformwordpress
AccesspressthemesEverest Timeline Lite Version1.1.1 SwPlatformwordpress
AccesspressthemesFashstore Version1.2.1 SwPlatformwordpress
AccesspressthemesForm Store To Db Version1.0.9 SwPlatformwordpress
AccesspressthemesFotography Version2.4.0 SwPlatformwordpress
AccesspressthemesGaga Corp Version1.0.8 SwPlatformwordpress
AccesspressthemesGaga Lite Version1.4.2 SwPlatformwordpress
AccesspressthemesInline Call To Action Builder Lite Version1.1.0 SwPlatformwordpress
AccesspressthemesMcontact Button SwPlatformwordpress Version < 2.0.7
AccesspressthemesOne-paze Version2.2.8 SwPlatformwordpress
AccesspressthemesParallax Blog Version3.1.1574941215 SwPlatformwordpress
AccesspressthemesParallaxsome Version1.3.6 SwPlatformwordpress
AccesspressthemesPi Button Version3.3.3 SwPlatformwordpress
AccesspressthemesProduct Slider For Woocommerce Lite Version1.1.5 SwPlatformwordpress
AccesspressthemesPunte Version1.1.2 SwPlatformwordpress
AccesspressthemesRevolve Version1.3.1 SwPlatformwordpress
AccesspressthemesRipple Version1.2.0 SwPlatformwordpress
AccesspressthemesScrollme Version2.1.0 SwPlatformwordpress
AccesspressthemesSmart Logo Showcase Lite Version1.1.7 SwPlatformwordpress
AccesspressthemesSmart Scroll Posts Version2.0.8 SwPlatformwordpress
AccesspressthemesSmart Scroll To Top Lite Version1.0.3 SwPlatformwordpress
AccesspressthemesSocial Auto Poster Version2.1.3 SwPlatformwordpress
AccesspressthemesSocial Review SwPlatformwordpress Version < 1.0.9
AccesspressthemesSportsmag Version1.2.1 SwPlatformwordpress
AccesspressthemesStorevilla Version1.4.1 SwPlatformwordpress
AccesspressthemesSwing Lite Version1.1.9 SwPlatformwordpress
AccesspressthemesTauto Poster Version1.4.5 SwPlatformwordpress
AccesspressthemesThe Launcher Version1.3.2 SwPlatformwordpress
AccesspressthemesThe Monday Version1.4.1 SwPlatformwordpress
AccesspressthemesTotal Gdpr Compliance Lite Version1.0.4 SwPlatformwordpress
AccesspressthemesTotal Team Lite Version1.1.1 SwPlatformwordpress
AccesspressthemesUltimate-form-builder-lite Version1.5.0 SwPlatformwordpress
AccesspressthemesUltimate Author Box Lite Version1.1.2 SwPlatformwordpress
AccesspressthemesUncode Lite Version1.3.1 SwPlatformwordpress
AccesspressthemesUnicon Lite Version1.2.6 SwPlatformwordpress
AccesspressthemesVmag Version1.2.7 SwPlatformwordpress
AccesspressthemesVmagazine Lite Version1.3.5 SwPlatformwordpress
AccesspressthemesVmagazine News Version1.0.5 SwPlatformwordpress
AccesspressthemesWp 1 Slider Version1.2.9 SwPlatformwordpress
AccesspressthemesWp Blog Manager Lite Version1.1.0 SwPlatformwordpress
AccesspressthemesWp Comment Designer Lite Version2.0.3 SwPlatformwordpress
AccesspressthemesWp Cookie User Info Version1.0.7 SwPlatformwordpress
AccesspressthemesWp Floating Menu Version1.4.4 SwPlatformwordpress
AccesspressthemesWp Media Manager Lite Version1.1.2 SwPlatformwordpress
AccesspressthemesWp Menu Icons Lite SwPlatformwordpress Version < 1.0.9
AccesspressthemesWp Popup Banners Version1.2.3 SwPlatformwordpress
AccesspressthemesWp Popup Lite Version1.0.8 SwPlatformwordpress
AccesspressthemesWp Product Gallery Lite Version1.1.1 SwPlatformwordpress
AccesspressthemesWp Tfeed Version1.6.7 SwPlatformwordpress
AccesspressthemesZigcy Baby Version1.0.6 SwPlatformwordpress
AccesspressthemesZigcy Cosmetics Version1.0.5 SwPlatformwordpress
AccesspressthemesZigcy Lite Version2.0.9 SwPlatformwordpress
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 6.69% 0.909
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-912 Hidden Functionality

The product contains functionality that is not documented, not part of the specification, and not accessible through an interface or command sequence that is obvious to the product's users or administrators.