CVE-2021-24867

CVE-2021-24867: Backdoored Plugins & Themes from AccessPress Themes

Vendor Accesspress Themes
Product Frontend Post WordPress Plugin – AccessPress Anonymous Post
Weakness CWE-912
Published February 21, 2022
Last update August 3, 2024

CVSS base score

What the vulnerability does

01Description

Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion

Key dates

02Disclosure timeline

February 21, 2022 CVE published
August 3, 2024 Record updated