CVE-2021-24867
critical-risk
Published 2022-02-21
Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion
Do I need to act?
~
6.7% chance of exploitation in next 30 days
EPSS score — moderate exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
9
CVSS 9.8/10
Critical
NETWORK
/ LOW complexity
Affected Products (20)
Accessbuddy
Accesspress Anonymous Post
Accesspress Basic
Accesspress Custom Css
Accesspress Custom Post Type
Accesspress Ifeeds
Accesspress Lite
Accesspress Mag
Accesspress Parallax
Accesspress Ray
Accesspress Root
Accesspress Social Counter
Accesspress Social Icons
Accesspress Social Login Lite
Accesspress Social Share
Accesspress Staple
Accesspress Store
Agency Lite
Ap Companion
Ap Contact Form
Affected Vendors
References (4)
71
/ 100
critical-risk
Severity
32/34 · Critical
Exploitability
9/34 · Low
Exposure
30/34 · Critical