CVE Vulnerabilities

CVE-2021-24867

Hidden Functionality

Published: Feb 21, 2022 | Modified: Mar 02, 2022
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion

Weakness

The product contains functionality that is not documented, not part of the specification, and not accessible through an interface or command sequence that is obvious to the product’s users or administrators.

Affected Software

Name Vendor Start Version End Version
Accessbuddy Accesspressthemes 1.0.0 (including) 1.0.0 (including)
Accesspress_anonymous_post Accesspressthemes 2.8.0 (including) 2.8.0 (including)
Accesspress_basic Accesspressthemes 3.2.1 (including) 3.2.1 (including)
Accesspress_custom_css Accesspressthemes 2.0.1 (including) 2.0.1 (including)
Accesspress_custom_post_type Accesspressthemes 1.0.8 (including) 1.0.8 (including)
Accesspress_ifeeds Accesspressthemes 4.0.3 (including) 4.0.3 (including)
Accesspress_lite Accesspressthemes 2.92 (including) 2.92 (including)
Accesspress_mag Accesspressthemes 2.6.5 (including) 2.6.5 (including)
Accesspress_parallax Accesspressthemes 4.5 (including) 4.5 (including)
Accesspress_ray Accesspressthemes 1.19.5 (including) 1.19.5 (including)
Accesspress_root Accesspressthemes 2.5 (including) 2.5 (including)
Accesspress_social_counter Accesspressthemes 1.9.1 (including) 1.9.1 (including)
Accesspress_social_icons Accesspressthemes 1.8.2 (including) 1.8.2 (including)
Accesspress_social_login_lite Accesspressthemes 3.4.7 (including) 3.4.7 (including)
Accesspress_social_share Accesspressthemes 4.5.5 (including) 4.5.5 (including)
Accesspress_staple Accesspressthemes 1.9.1 (including) 1.9.1 (including)
Accesspress_store Accesspressthemes 2.4.9 (including) 2.4.9 (including)
Agency_lite Accesspressthemes 1.1.6 (including) 1.1.6 (including)
Ap_companion Accesspressthemes * 1.0.7 (excluding)
Ap_contact_form Accesspressthemes 1.0.6 (including) 1.0.6 (including)
Ap_custom_testimonial Accesspressthemes 1.4.6 (including) 1.4.6 (including)
Ap_mega_menu Accesspressthemes 3.0.5 (including) 3.0.5 (including)
Ap_pricing_tables_lite Accesspressthemes 1.1.2 (including) 1.1.2 (including)
Apex_notification_bar_lite Accesspressthemes 2.0.4 (including) 2.0.4 (including)
Aplite Accesspressthemes 1.0.6 (including) 1.0.6 (including)
Badge_designer_lite_for_woocommerce Accesspressthemes 1.1.0 (including) 1.1.0 (including)
Bingle Accesspressthemes 1.0.4 (including) 1.0.4 (including)
Bloger Accesspressthemes 1.2.6 (including) 1.2.6 (including)
Comments_disable_-_accesspress Accesspressthemes 1.0.7 (including) 1.0.7 (including)
Construction_lite Accesspressthemes 1.2.5 (including) 1.2.5 (including)
Doko Accesspressthemes 1.0.27 (including) 1.0.27 (including)
Easy_side_tab Accesspressthemes 1.0.7 (including) 1.0.7 (including)
Enlighten Accesspressthemes 1.3.5 (including) 1.3.5 (including)
Everest_admin_theme_lite Accesspressthemes 1.0.7 (including) 1.0.7 (including)
Everest_coming_soon_lite Accesspressthemes 1.1.0 (including) 1.1.0 (including)
Everest_comment_rating_lite Accesspressthemes 2.0.4 (including) 2.0.4 (including)
Everest_counter_lite Accesspressthemes 2.0.7 (including) 2.0.7 (including)
Everest_faq_manager_lite Accesspressthemes 1.0.8 (including) 1.0.8 (including)
Everest_gallery_lite Accesspressthemes 1.0.8 (including) 1.0.8 (including)
Everest_gplaces_business_reviews Accesspressthemes 1.0.9 (including) 1.0.9 (including)
Everest_review_lite Accesspressthemes 1.0.7 (including) 1.0.7 (including)
Everest_tab_lite Accesspressthemes 2.0.3 (including) 2.0.3 (including)
Everest_timeline_lite Accesspressthemes 1.1.1 (including) 1.1.1 (including)
Fashstore Accesspressthemes 1.2.1 (including) 1.2.1 (including)
Form_store_to_db Accesspressthemes 1.0.9 (including) 1.0.9 (including)
Fotography Accesspressthemes 2.4.0 (including) 2.4.0 (including)
Gaga_corp Accesspressthemes 1.0.8 (including) 1.0.8 (including)
Gaga_lite Accesspressthemes 1.4.2 (including) 1.4.2 (including)
Inline_call_to_action_builder_lite Accesspressthemes 1.1.0 (including) 1.1.0 (including)
Mcontact_button Accesspressthemes * 2.0.7 (excluding)
One-paze Accesspressthemes 2.2.8 (including) 2.2.8 (including)
Parallax_blog Accesspressthemes 3.1.1574941215 (including) 3.1.1574941215 (including)
Parallaxsome Accesspressthemes 1.3.6 (including) 1.3.6 (including)
Pi_button Accesspressthemes 3.3.3 (including) 3.3.3 (including)
Product_slider_for_woocommerce_lite Accesspressthemes 1.1.5 (including) 1.1.5 (including)
Punte Accesspressthemes 1.1.2 (including) 1.1.2 (including)
Revolve Accesspressthemes 1.3.1 (including) 1.3.1 (including)
Ripple Accesspressthemes 1.2.0 (including) 1.2.0 (including)
Scrollme Accesspressthemes 2.1.0 (including) 2.1.0 (including)
Smart_logo_showcase_lite Accesspressthemes 1.1.7 (including) 1.1.7 (including)
Smart_scroll_posts Accesspressthemes 2.0.8 (including) 2.0.8 (including)
Smart_scroll_to_top_lite Accesspressthemes 1.0.3 (including) 1.0.3 (including)
Social_auto_poster Accesspressthemes 2.1.3 (including) 2.1.3 (including)
Social_review Accesspressthemes * 1.0.9 (excluding)
Sportsmag Accesspressthemes 1.2.1 (including) 1.2.1 (including)
Storevilla Accesspressthemes 1.4.1 (including) 1.4.1 (including)
Swing_lite Accesspressthemes 1.1.9 (including) 1.1.9 (including)
Tauto_poster Accesspressthemes 1.4.5 (including) 1.4.5 (including)
The_launcher Accesspressthemes 1.3.2 (including) 1.3.2 (including)
The_monday Accesspressthemes 1.4.1 (including) 1.4.1 (including)
Total_gdpr_compliance_lite Accesspressthemes 1.0.4 (including) 1.0.4 (including)
Total_team_lite Accesspressthemes 1.1.1 (including) 1.1.1 (including)
Ultimate-form-builder-lite Accesspressthemes 1.5.0 (including) 1.5.0 (including)
Ultimate_author_box_lite Accesspressthemes 1.1.2 (including) 1.1.2 (including)
Uncode_lite Accesspressthemes 1.3.1 (including) 1.3.1 (including)
Unicon_lite Accesspressthemes 1.2.6 (including) 1.2.6 (including)
Vmag Accesspressthemes 1.2.7 (including) 1.2.7 (including)
Vmagazine_lite Accesspressthemes 1.3.5 (including) 1.3.5 (including)
Vmagazine_news Accesspressthemes 1.0.5 (including) 1.0.5 (including)
Wp_1_slider Accesspressthemes 1.2.9 (including) 1.2.9 (including)
Wp_blog_manager_lite Accesspressthemes 1.1.0 (including) 1.1.0 (including)
Wp_comment_designer_lite Accesspressthemes 2.0.3 (including) 2.0.3 (including)
Wp_cookie_user_info Accesspressthemes 1.0.7 (including) 1.0.7 (including)
Wp_floating_menu Accesspressthemes 1.4.4 (including) 1.4.4 (including)
Wp_media_manager_lite Accesspressthemes 1.1.2 (including) 1.1.2 (including)
Wp_menu_icons_lite Accesspressthemes * 1.0.9 (excluding)
Wp_popup_banners Accesspressthemes 1.2.3 (including) 1.2.3 (including)
Wp_popup_lite Accesspressthemes 1.0.8 (including) 1.0.8 (including)
Wp_product_gallery_lite Accesspressthemes 1.1.1 (including) 1.1.1 (including)
Wp_tfeed Accesspressthemes 1.6.7 (including) 1.6.7 (including)
Zigcy_baby Accesspressthemes 1.0.6 (including) 1.0.6 (including)
Zigcy_cosmetics Accesspressthemes 1.0.5 (including) 1.0.5 (including)
Zigcy_lite Accesspressthemes 2.0.9 (including) 2.0.9 (including)

Potential Mitigations

References