AccessPress Anonymous Post = 2.8.0 - Backdoored
2021-10-13 00:00
Harald EilertsenStrategic Overview
StatusPatched in 2.8.1
Affected PluginFrontend Post WordPress Plugin – AccessPress Anonymous Post
Affected Version
2.8.0CVSS8.8High
CVE
CVE-2021-24867Vulnerability Overview
Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion
Technical Analysis
REMEDIATION: Update to version 2.8.1, or a newer patched version --- IDENTIFIER: CWE-912 (Hidden Functionality) The product contains functionality that is not documented, not part of the specification, and not accessible through an interface or command sequence that is obvious to the product's users or administrators.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C