We found results for “”
CVE-2021-24867
Good to know:
Date: February 21, 2022
Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion
Language: PHP
Severity Score
Severity Score
Weakness Type (CWE)
Hidden Functionality
CWE-912Top Fix
Upgrade Version
Upgrade to version accesspress-anonymous-post - 2.8.1/;accesspress-custom-css - 2.0.2/; accesspress-custom-post-type - 1.0.9/;accesspress-facebook-auto-post - 2.1.4/;accesspress-instagram-feed - 4.0.4/;accesspress-pinterest - 3.3.4/;accesspress-social-counter - 1.9.2/;accesspress-social-icons - 1.8.3/;accesspress-social-login-lite - 3.4.8/;accesspress-social-share - 4.5.6/
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | HIGH |
Integrity (I): | HIGH |
Availability (A): | HIGH |
CVSS v2
Base Score: |
|
---|---|
Access Vector (AV): | NETWORK |
Access Complexity (AC): | LOW |
Authentication (AU): | NONE |
Confidentiality (C): | PARTIAL |
Integrity (I): | PARTIAL |
Availability (A): | PARTIAL |
Additional information: |