CVE-2021-24867
Summary
| CVE | CVE-2021-24867 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-02-21 11:15:00 UTC |
| Updated | 2022-03-02 18:03:00 UTC |
| Description | Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion |
Risk And Classification
Problem Types: CWE-912
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Backdoored Plugins & Themes from AccessPress Themes WordPress Security Vulnerability | MISC | wpscan.com | |
| Backdoor Found in Themes and Plugins from AccessPress Themes | MISC | jetpack.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Harald Eilertsen (Jetpack Scan)
Legacy QID Mappings
- 730374 WordPress Plugin WP Data Access SQL Injection Vulnerability