CVE-2021-24867

CRITICALCVSS 9.8/10EPSS 18.88%

Last modified

CVE-2021-24867 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. EPSS estimates a 18.88% chance of exploitation in the next 30 days.

Description

Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion

Metrics

CVSS 3.1
9.8/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
18.88%

96.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
AccesspressthemesAccessbuddy1.0.0
AccesspressthemesAccesspress Anonymous Post2.8.0
AccesspressthemesAccesspress Basic3.2.1
AccesspressthemesAccesspress Custom Css2.0.1
AccesspressthemesAccesspress Custom Post Type1.0.8
AccesspressthemesAccesspress Ifeeds4.0.3
AccesspressthemesAccesspress Lite2.92
AccesspressthemesAccesspress Mag2.6.5
AccesspressthemesAccesspress Parallax4.5
AccesspressthemesAccesspress Ray1.19.5
AccesspressthemesAccesspress Root2.5
AccesspressthemesAccesspress Social Counter1.9.1
AccesspressthemesAccesspress Social Icons1.8.2
AccesspressthemesAccesspress Social Login Lite3.4.7
AccesspressthemesAccesspress Social Share4.5.5
AccesspressthemesAccesspress Staple1.9.1
AccesspressthemesAccesspress Store2.4.9
AccesspressthemesAgency Lite1.1.6
AccesspressthemesAp Companion< 1.0.7
AccesspressthemesAp Contact Form1.0.6
AccesspressthemesAp Custom Testimonial1.4.6
AccesspressthemesAp Mega Menu3.0.5
AccesspressthemesAp Pricing Tables Lite1.1.2
AccesspressthemesApex Notification Bar Lite2.0.4
AccesspressthemesAplite1.0.6
AccesspressthemesBadge Designer Lite For Woocommerce1.1.0
AccesspressthemesBingle1.0.4
AccesspressthemesBloger1.2.6
AccesspressthemesComments Disable - Accesspress1.0.7
AccesspressthemesConstruction Lite1.2.5
AccesspressthemesDoko1.0.27
AccesspressthemesEasy Side Tab1.0.7
AccesspressthemesEnlighten1.3.5
AccesspressthemesEverest Admin Theme Lite1.0.7
AccesspressthemesEverest Coming Soon Lite1.1.0
AccesspressthemesEverest Comment Rating Lite2.0.4
AccesspressthemesEverest Counter Lite2.0.7
AccesspressthemesEverest Faq Manager Lite1.0.8
AccesspressthemesEverest Gallery Lite1.0.8
AccesspressthemesEverest Gplaces Business Reviews1.0.9
AccesspressthemesEverest Review Lite1.0.7
AccesspressthemesEverest Tab Lite2.0.3
AccesspressthemesEverest Timeline Lite1.1.1
AccesspressthemesFashstore1.2.1
AccesspressthemesForm Store To Db1.0.9
AccesspressthemesFotography2.4.0
AccesspressthemesGaga Corp1.0.8
AccesspressthemesGaga Lite1.4.2
AccesspressthemesInline Call To Action Builder Lite1.1.0
AccesspressthemesMcontact Button< 2.0.7

Showing 50 of 93 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2021-24867?
Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion
How severe is CVE-2021-24867?
CVE-2021-24867 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 18.88% probability of exploitation in the next 30 days.
How do I fix CVE-2021-24867?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2021-24867?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST