CVE-2021-24867
Dashboard / Vulnerabilities / CVE-2021-24867
CVE-2021-24867
Published: 21 Feb 2022Last Modified: 10 Apr 2026
Summary:
Details: Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion
References: https://jetpack.com/2022/01/18/backdoor-found-in-themes-and-plugins-from-accesspress-themes/, https://wpscan.com/vulnerability/9c76bada-fa32-4c2f-9855-d0efd1e63eff
Affected packages
Package
Name:
Purl:
Affected ranges
Affected versions
1.0.6
1.0.7
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
