AccessPress Social Icons 1.8.2 - Backdoor
2022-01-18 00:00
Harald EilertsenStrategic Overview
Vulnerability Overview
The AccessPress Social Icons plugin for WordPress contains a backdoor when downloaded directly from the AccessPress site in version 1.8.2. This allows attackers to gain full control of a site with the plugin installed.
Technical Analysis
REMEDIATION: Update to version 1.8.3, or a newer patched version --- IDENTIFIER: CWE-912 (Hidden Functionality) The product contains functionality that is not documented, not part of the specification, and not accessible through an interface or command sequence that is obvious to the product's users or administrators.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C