CVE-2021-24867 | Backdoored Plugins & Themes from AccessPress Themes

Exp

Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion

Published: 2022-02-21 Last update: 2026-06-16 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2021-24867 is rated High Exploit Risk (93.1/100): CVSS Critical severity, with high exploitation likelihood (EPSS 18.88%, 97th percentile). Core evidence: 2 public exploit reference(s) are indexed (Exploit-DB). EPSS rose +14.12% over the last day, indicating growing attacker interest. Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Public exploit references (Exploit-DB) for CVE-2021-24867

EDB-ID Source Kind Published Link
nvd_ref exploit_tag Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗

Exploit prediction scoring system (EPSS) score for CVE-2021-24867

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 4.75% 18.88% +14.12%
2 2026-04-27 6.69% 4.75% -1.93%
3 2025-11-21 6.69%

Full EPSS history (17 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2021-24867

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
9.8 3.1 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Click to expand
Attack vector (AV:N)
Could be attacked over the internet or any normal routed network—not just someone sitting at the machine.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:N)
No account or special rights needed—anonymous or random user is enough.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:H)
Serious risk that confidential data gets exposed in a big way.
Integrity (I:H)
They could widely tamper with or forge data—trust in the data is badly hurt.
Availability (A:H)
Could take the service down hard or make it unusable for people who depend on it.
3.9 5.9 [email protected]
7.5 2.0 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:P)
Partial confidentiality impact.
Integrity impact (I:P)
Partial integrity impact.
Availability impact (A:P)
Partial availability impact.
10.0 6.4 [email protected]

Weakness enumeration for CVE-2021-24867

Affected software / configurations for CVE-2021-24867

Vendor Product Version Raw CPE
accesspressthemes accessbuddy 1.0.0 cpe:2.3:a:accesspressthemes:accessbuddy:1.0.0:*:*:*:*:wordpress:*:*
accesspressthemes accesspress_anonymous_post 2.8.0 cpe:2.3:a:accesspressthemes:accesspress_anonymous_post:2.8.0:*:*:*:*:wordpress:*:*
accesspressthemes accesspress_basic 3.2.1 cpe:2.3:a:accesspressthemes:accesspress_basic:3.2.1:*:*:*:*:wordpress:*:*
accesspressthemes accesspress_custom_css 2.0.1 cpe:2.3:a:accesspressthemes:accesspress_custom_css:2.0.1:*:*:*:*:wordpress:*:*
accesspressthemes accesspress_custom_post_type 1.0.8 cpe:2.3:a:accesspressthemes:accesspress_custom_post_type:1.0.8:*:*:*:*:wordpress:*:*
accesspressthemes accesspress_ifeeds 4.0.3 cpe:2.3:a:accesspressthemes:accesspress_ifeeds:4.0.3:*:*:*:*:wordpress:*:*
accesspressthemes accesspress_lite 2.92 cpe:2.3:a:accesspressthemes:accesspress_lite:2.92:*:*:*:*:wordpress:*:*
accesspressthemes accesspress_mag 2.6.5 cpe:2.3:a:accesspressthemes:accesspress_mag:2.6.5:*:*:*:*:wordpress:*:*
accesspressthemes accesspress_parallax 4.5 cpe:2.3:a:accesspressthemes:accesspress_parallax:4.5:*:*:*:*:wordpress:*:*
accesspressthemes accesspress_ray 1.19.5 cpe:2.3:a:accesspressthemes:accesspress_ray:1.19.5:*:*:*:*:wordpress:*:*
accesspressthemes accesspress_root 2.5 cpe:2.3:a:accesspressthemes:accesspress_root:2.5:*:*:*:*:wordpress:*:*
accesspressthemes accesspress_social_counter 1.9.1 cpe:2.3:a:accesspressthemes:accesspress_social_counter:1.9.1:*:*:*:*:wordpress:*:*
accesspressthemes accesspress_social_icons 1.8.2 cpe:2.3:a:accesspressthemes:accesspress_social_icons:1.8.2:*:*:*:*:wordpress:*:*
accesspressthemes accesspress_social_login_lite 3.4.7 cpe:2.3:a:accesspressthemes:accesspress_social_login_lite:3.4.7:*:*:*:*:wordpress:*:*
accesspressthemes accesspress_social_share 4.5.5 cpe:2.3:a:accesspressthemes:accesspress_social_share:4.5.5:*:*:*:*:wordpress:*:*
accesspressthemes accesspress_staple 1.9.1 cpe:2.3:a:accesspressthemes:accesspress_staple:1.9.1:*:*:*:*:wordpress:*:*
accesspressthemes accesspress_store 2.4.9 cpe:2.3:a:accesspressthemes:accesspress_store:2.4.9:*:*:*:*:wordpress:*:*
accesspressthemes agency_lite 1.1.6 cpe:2.3:a:accesspressthemes:agency_lite:1.1.6:*:*:*:*:wordpress:*:*
accesspressthemes ap_companion < 1.0.7 cpe:2.3:a:accesspressthemes:ap_companion:*:*:*:*:*:wordpress:*:*
accesspressthemes ap_contact_form 1.0.6 cpe:2.3:a:accesspressthemes:ap_contact_form:1.0.6:*:*:*:*:wordpress:*:*
accesspressthemes ap_custom_testimonial 1.4.6 cpe:2.3:a:accesspressthemes:ap_custom_testimonial:1.4.6:*:*:*:*:wordpress:*:*
accesspressthemes ap_mega_menu 3.0.5 cpe:2.3:a:accesspressthemes:ap_mega_menu:3.0.5:*:*:*:*:wordpress:*:*
accesspressthemes ap_pricing_tables_lite 1.1.2 cpe:2.3:a:accesspressthemes:ap_pricing_tables_lite:1.1.2:*:*:*:*:wordpress:*:*
accesspressthemes apex_notification_bar_lite 2.0.4 cpe:2.3:a:accesspressthemes:apex_notification_bar_lite:2.0.4:*:*:*:*:wordpress:*:*
accesspressthemes aplite 1.0.6 cpe:2.3:a:accesspressthemes:aplite:1.0.6:*:*:*:*:wordpress:*:*
accesspressthemes badge_designer_lite_for_woocommerce 1.1.0 cpe:2.3:a:accesspressthemes:badge_designer_lite_for_woocommerce:1.1.0:*:*:*:*:wordpress:*:*
accesspressthemes bingle 1.0.4 cpe:2.3:a:accesspressthemes:bingle:1.0.4:*:*:*:*:wordpress:*:*
accesspressthemes bloger 1.2.6 cpe:2.3:a:accesspressthemes:bloger:1.2.6:*:*:*:*:wordpress:*:*
accesspressthemes comments_disable_-_accesspress 1.0.7 cpe:2.3:a:accesspressthemes:comments_disable_-_accesspress:1.0.7:*:*:*:*:wordpress:*:*
accesspressthemes construction_lite 1.2.5 cpe:2.3:a:accesspressthemes:construction_lite:1.2.5:*:*:*:*:wordpress:*:*
accesspressthemes doko 1.0.27 cpe:2.3:a:accesspressthemes:doko:1.0.27:*:*:*:*:wordpress:*:*
accesspressthemes easy_side_tab 1.0.7 cpe:2.3:a:accesspressthemes:easy_side_tab:1.0.7:*:*:*:*:wordpress:*:*
accesspressthemes enlighten 1.3.5 cpe:2.3:a:accesspressthemes:enlighten:1.3.5:*:*:*:*:wordpress:*:*
accesspressthemes everest_admin_theme_lite 1.0.7 cpe:2.3:a:accesspressthemes:everest_admin_theme_lite:1.0.7:*:*:*:*:wordpress:*:*
accesspressthemes everest_coming_soon_lite 1.1.0 cpe:2.3:a:accesspressthemes:everest_coming_soon_lite:1.1.0:*:*:*:*:wordpress:*:*
accesspressthemes everest_comment_rating_lite 2.0.4 cpe:2.3:a:accesspressthemes:everest_comment_rating_lite:2.0.4:*:*:*:*:wordpress:*:*
accesspressthemes everest_counter_lite 2.0.7 cpe:2.3:a:accesspressthemes:everest_counter_lite:2.0.7:*:*:*:*:wordpress:*:*
accesspressthemes everest_faq_manager_lite 1.0.8 cpe:2.3:a:accesspressthemes:everest_faq_manager_lite:1.0.8:*:*:*:*:wordpress:*:*
accesspressthemes everest_gallery_lite 1.0.8 cpe:2.3:a:accesspressthemes:everest_gallery_lite:1.0.8:*:*:*:*:wordpress:*:*
accesspressthemes everest_gplaces_business_reviews 1.0.9 cpe:2.3:a:accesspressthemes:everest_gplaces_business_reviews:1.0.9:*:*:*:*:wordpress:*:*
accesspressthemes everest_review_lite 1.0.7 cpe:2.3:a:accesspressthemes:everest_review_lite:1.0.7:*:*:*:*:wordpress:*:*
accesspressthemes everest_tab_lite 2.0.3 cpe:2.3:a:accesspressthemes:everest_tab_lite:2.0.3:*:*:*:*:wordpress:*:*
accesspressthemes everest_timeline_lite 1.1.1 cpe:2.3:a:accesspressthemes:everest_timeline_lite:1.1.1:*:*:*:*:wordpress:*:*
accesspressthemes fashstore 1.2.1 cpe:2.3:a:accesspressthemes:fashstore:1.2.1:*:*:*:*:wordpress:*:*
accesspressthemes form_store_to_db 1.0.9 cpe:2.3:a:accesspressthemes:form_store_to_db:1.0.9:*:*:*:*:wordpress:*:*
accesspressthemes fotography 2.4.0 cpe:2.3:a:accesspressthemes:fotography:2.4.0:*:*:*:*:wordpress:*:*
accesspressthemes gaga_corp 1.0.8 cpe:2.3:a:accesspressthemes:gaga_corp:1.0.8:*:*:*:*:wordpress:*:*
accesspressthemes gaga_lite 1.4.2 cpe:2.3:a:accesspressthemes:gaga_lite:1.4.2:*:*:*:*:wordpress:*:*
accesspressthemes inline_call_to_action_builder_lite 1.1.0 cpe:2.3:a:accesspressthemes:inline_call_to_action_builder_lite:1.1.0:*:*:*:*:wordpress:*:*
accesspressthemes mcontact_button < 2.0.7 cpe:2.3:a:accesspressthemes:mcontact_button:*:*:*:*:*:wordpress:*:*
accesspressthemes one-paze 2.2.8 cpe:2.3:a:accesspressthemes:one-paze:2.2.8:*:*:*:*:wordpress:*:*
accesspressthemes parallax_blog 3.1.1574941215 cpe:2.3:a:accesspressthemes:parallax_blog:3.1.1574941215:*:*:*:*:wordpress:*:*
accesspressthemes parallaxsome 1.3.6 cpe:2.3:a:accesspressthemes:parallaxsome:1.3.6:*:*:*:*:wordpress:*:*
accesspressthemes pi_button 3.3.3 cpe:2.3:a:accesspressthemes:pi_button:3.3.3:*:*:*:*:wordpress:*:*
accesspressthemes product_slider_for_woocommerce_lite 1.1.5 cpe:2.3:a:accesspressthemes:product_slider_for_woocommerce_lite:1.1.5:*:*:*:*:wordpress:*:*
accesspressthemes punte 1.1.2 cpe:2.3:a:accesspressthemes:punte:1.1.2:*:*:*:*:wordpress:*:*
accesspressthemes revolve 1.3.1 cpe:2.3:a:accesspressthemes:revolve:1.3.1:*:*:*:*:wordpress:*:*
accesspressthemes ripple 1.2.0 cpe:2.3:a:accesspressthemes:ripple:1.2.0:*:*:*:*:wordpress:*:*
accesspressthemes scrollme 2.1.0 cpe:2.3:a:accesspressthemes:scrollme:2.1.0:*:*:*:*:wordpress:*:*
accesspressthemes smart_logo_showcase_lite 1.1.7 cpe:2.3:a:accesspressthemes:smart_logo_showcase_lite:1.1.7:*:*:*:*:wordpress:*:*
accesspressthemes smart_scroll_posts 2.0.8 cpe:2.3:a:accesspressthemes:smart_scroll_posts:2.0.8:*:*:*:*:wordpress:*:*
accesspressthemes smart_scroll_to_top_lite 1.0.3 cpe:2.3:a:accesspressthemes:smart_scroll_to_top_lite:1.0.3:*:*:*:*:wordpress:*:*
accesspressthemes social_auto_poster 2.1.3 cpe:2.3:a:accesspressthemes:social_auto_poster:2.1.3:*:*:*:*:wordpress:*:*
accesspressthemes social_review < 1.0.9 cpe:2.3:a:accesspressthemes:social_review:*:*:*:*:*:wordpress:*:*
accesspressthemes sportsmag 1.2.1 cpe:2.3:a:accesspressthemes:sportsmag:1.2.1:*:*:*:*:wordpress:*:*
accesspressthemes storevilla 1.4.1 cpe:2.3:a:accesspressthemes:storevilla:1.4.1:*:*:*:*:wordpress:*:*
accesspressthemes swing_lite 1.1.9 cpe:2.3:a:accesspressthemes:swing_lite:1.1.9:*:*:*:*:wordpress:*:*
accesspressthemes tauto_poster 1.4.5 cpe:2.3:a:accesspressthemes:tauto_poster:1.4.5:*:*:*:*:wordpress:*:*
accesspressthemes the_launcher 1.3.2 cpe:2.3:a:accesspressthemes:the_launcher:1.3.2:*:*:*:*:wordpress:*:*
accesspressthemes the_monday 1.4.1 cpe:2.3:a:accesspressthemes:the_monday:1.4.1:*:*:*:*:wordpress:*:*
accesspressthemes total_gdpr_compliance_lite 1.0.4 cpe:2.3:a:accesspressthemes:total_gdpr_compliance_lite:1.0.4:*:*:*:*:wordpress:*:*
accesspressthemes total_team_lite 1.1.1 cpe:2.3:a:accesspressthemes:total_team_lite:1.1.1:*:*:*:*:wordpress:*:*
accesspressthemes ultimate-form-builder-lite 1.5.0 cpe:2.3:a:accesspressthemes:ultimate-form-builder-lite:1.5.0:*:*:*:*:wordpress:*:*
accesspressthemes ultimate_author_box_lite 1.1.2 cpe:2.3:a:accesspressthemes:ultimate_author_box_lite:1.1.2:*:*:*:*:wordpress:*:*
accesspressthemes uncode_lite 1.3.1 cpe:2.3:a:accesspressthemes:uncode_lite:1.3.1:*:*:*:*:wordpress:*:*
accesspressthemes unicon_lite 1.2.6 cpe:2.3:a:accesspressthemes:unicon_lite:1.2.6:*:*:*:*:wordpress:*:*
accesspressthemes vmag 1.2.7 cpe:2.3:a:accesspressthemes:vmag:1.2.7:*:*:*:*:wordpress:*:*
accesspressthemes vmagazine_lite 1.3.5 cpe:2.3:a:accesspressthemes:vmagazine_lite:1.3.5:*:*:*:*:wordpress:*:*
accesspressthemes vmagazine_news 1.0.5 cpe:2.3:a:accesspressthemes:vmagazine_news:1.0.5:*:*:*:*:wordpress:*:*
accesspressthemes wp_1_slider 1.2.9 cpe:2.3:a:accesspressthemes:wp_1_slider:1.2.9:*:*:*:*:wordpress:*:*

References for CVE-2021-24867

cvelogic Threat Intelligence