Backdoored Plugins & Themes from AccessPress Themes
Vulnerability Description
Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-24867
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Harald Eilertsen (Jetpack Scan)
References
More from AccessPress Themes
View All →Affected Vendor
AccessPress Themes
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.