Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion
Conclusion & alert: CVE-2021-24867 is rated High Exploit Risk (93.1/100): CVSS Critical severity, with high exploitation likelihood (EPSS 18.88%, 97th percentile). Core evidence: 2 public exploit reference(s) are indexed (Exploit-DB). EPSS rose +14.12% over the last day, indicating growing attacker interest. Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ | |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 4.75% | 18.88% | +14.12% |
| 2 | 2026-04-27 | 6.69% | 4.75% | -1.93% |
| 3 | 2025-11-21 | — | 6.69% | — |
Full EPSS history (17 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
| 7.5 | 2.0 | HIGH |
|
10.0 | 6.4 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| accesspressthemes | accessbuddy | 1.0.0 | cpe:2.3:a:accesspressthemes:accessbuddy:1.0.0:*:*:*:*:wordpress:*:* |
| accesspressthemes | accesspress_anonymous_post | 2.8.0 | cpe:2.3:a:accesspressthemes:accesspress_anonymous_post:2.8.0:*:*:*:*:wordpress:*:* |
| accesspressthemes | accesspress_basic | 3.2.1 | cpe:2.3:a:accesspressthemes:accesspress_basic:3.2.1:*:*:*:*:wordpress:*:* |
| accesspressthemes | accesspress_custom_css | 2.0.1 | cpe:2.3:a:accesspressthemes:accesspress_custom_css:2.0.1:*:*:*:*:wordpress:*:* |
| accesspressthemes | accesspress_custom_post_type | 1.0.8 | cpe:2.3:a:accesspressthemes:accesspress_custom_post_type:1.0.8:*:*:*:*:wordpress:*:* |
| accesspressthemes | accesspress_ifeeds | 4.0.3 | cpe:2.3:a:accesspressthemes:accesspress_ifeeds:4.0.3:*:*:*:*:wordpress:*:* |
| accesspressthemes | accesspress_lite | 2.92 | cpe:2.3:a:accesspressthemes:accesspress_lite:2.92:*:*:*:*:wordpress:*:* |
| accesspressthemes | accesspress_mag | 2.6.5 | cpe:2.3:a:accesspressthemes:accesspress_mag:2.6.5:*:*:*:*:wordpress:*:* |
| accesspressthemes | accesspress_parallax | 4.5 | cpe:2.3:a:accesspressthemes:accesspress_parallax:4.5:*:*:*:*:wordpress:*:* |
| accesspressthemes | accesspress_ray | 1.19.5 | cpe:2.3:a:accesspressthemes:accesspress_ray:1.19.5:*:*:*:*:wordpress:*:* |
| accesspressthemes | accesspress_root | 2.5 | cpe:2.3:a:accesspressthemes:accesspress_root:2.5:*:*:*:*:wordpress:*:* |
| accesspressthemes | accesspress_social_counter | 1.9.1 | cpe:2.3:a:accesspressthemes:accesspress_social_counter:1.9.1:*:*:*:*:wordpress:*:* |
| accesspressthemes | accesspress_social_icons | 1.8.2 | cpe:2.3:a:accesspressthemes:accesspress_social_icons:1.8.2:*:*:*:*:wordpress:*:* |
| accesspressthemes | accesspress_social_login_lite | 3.4.7 | cpe:2.3:a:accesspressthemes:accesspress_social_login_lite:3.4.7:*:*:*:*:wordpress:*:* |
| accesspressthemes | accesspress_social_share | 4.5.5 | cpe:2.3:a:accesspressthemes:accesspress_social_share:4.5.5:*:*:*:*:wordpress:*:* |
| accesspressthemes | accesspress_staple | 1.9.1 | cpe:2.3:a:accesspressthemes:accesspress_staple:1.9.1:*:*:*:*:wordpress:*:* |
| accesspressthemes | accesspress_store | 2.4.9 | cpe:2.3:a:accesspressthemes:accesspress_store:2.4.9:*:*:*:*:wordpress:*:* |
| accesspressthemes | agency_lite | 1.1.6 | cpe:2.3:a:accesspressthemes:agency_lite:1.1.6:*:*:*:*:wordpress:*:* |
| accesspressthemes | ap_companion | < 1.0.7 | cpe:2.3:a:accesspressthemes:ap_companion:*:*:*:*:*:wordpress:*:* |
| accesspressthemes | ap_contact_form | 1.0.6 | cpe:2.3:a:accesspressthemes:ap_contact_form:1.0.6:*:*:*:*:wordpress:*:* |
| accesspressthemes | ap_custom_testimonial | 1.4.6 | cpe:2.3:a:accesspressthemes:ap_custom_testimonial:1.4.6:*:*:*:*:wordpress:*:* |
| accesspressthemes | ap_mega_menu | 3.0.5 | cpe:2.3:a:accesspressthemes:ap_mega_menu:3.0.5:*:*:*:*:wordpress:*:* |
| accesspressthemes | ap_pricing_tables_lite | 1.1.2 | cpe:2.3:a:accesspressthemes:ap_pricing_tables_lite:1.1.2:*:*:*:*:wordpress:*:* |
| accesspressthemes | apex_notification_bar_lite | 2.0.4 | cpe:2.3:a:accesspressthemes:apex_notification_bar_lite:2.0.4:*:*:*:*:wordpress:*:* |
| accesspressthemes | aplite | 1.0.6 | cpe:2.3:a:accesspressthemes:aplite:1.0.6:*:*:*:*:wordpress:*:* |
| accesspressthemes | badge_designer_lite_for_woocommerce | 1.1.0 | cpe:2.3:a:accesspressthemes:badge_designer_lite_for_woocommerce:1.1.0:*:*:*:*:wordpress:*:* |
| accesspressthemes | bingle | 1.0.4 | cpe:2.3:a:accesspressthemes:bingle:1.0.4:*:*:*:*:wordpress:*:* |
| accesspressthemes | bloger | 1.2.6 | cpe:2.3:a:accesspressthemes:bloger:1.2.6:*:*:*:*:wordpress:*:* |
| accesspressthemes | comments_disable_-_accesspress | 1.0.7 | cpe:2.3:a:accesspressthemes:comments_disable_-_accesspress:1.0.7:*:*:*:*:wordpress:*:* |
| accesspressthemes | construction_lite | 1.2.5 | cpe:2.3:a:accesspressthemes:construction_lite:1.2.5:*:*:*:*:wordpress:*:* |
| accesspressthemes | doko | 1.0.27 | cpe:2.3:a:accesspressthemes:doko:1.0.27:*:*:*:*:wordpress:*:* |
| accesspressthemes | easy_side_tab | 1.0.7 | cpe:2.3:a:accesspressthemes:easy_side_tab:1.0.7:*:*:*:*:wordpress:*:* |
| accesspressthemes | enlighten | 1.3.5 | cpe:2.3:a:accesspressthemes:enlighten:1.3.5:*:*:*:*:wordpress:*:* |
| accesspressthemes | everest_admin_theme_lite | 1.0.7 | cpe:2.3:a:accesspressthemes:everest_admin_theme_lite:1.0.7:*:*:*:*:wordpress:*:* |
| accesspressthemes | everest_coming_soon_lite | 1.1.0 | cpe:2.3:a:accesspressthemes:everest_coming_soon_lite:1.1.0:*:*:*:*:wordpress:*:* |
| accesspressthemes | everest_comment_rating_lite | 2.0.4 | cpe:2.3:a:accesspressthemes:everest_comment_rating_lite:2.0.4:*:*:*:*:wordpress:*:* |
| accesspressthemes | everest_counter_lite | 2.0.7 | cpe:2.3:a:accesspressthemes:everest_counter_lite:2.0.7:*:*:*:*:wordpress:*:* |
| accesspressthemes | everest_faq_manager_lite | 1.0.8 | cpe:2.3:a:accesspressthemes:everest_faq_manager_lite:1.0.8:*:*:*:*:wordpress:*:* |
| accesspressthemes | everest_gallery_lite | 1.0.8 | cpe:2.3:a:accesspressthemes:everest_gallery_lite:1.0.8:*:*:*:*:wordpress:*:* |
| accesspressthemes | everest_gplaces_business_reviews | 1.0.9 | cpe:2.3:a:accesspressthemes:everest_gplaces_business_reviews:1.0.9:*:*:*:*:wordpress:*:* |
| accesspressthemes | everest_review_lite | 1.0.7 | cpe:2.3:a:accesspressthemes:everest_review_lite:1.0.7:*:*:*:*:wordpress:*:* |
| accesspressthemes | everest_tab_lite | 2.0.3 | cpe:2.3:a:accesspressthemes:everest_tab_lite:2.0.3:*:*:*:*:wordpress:*:* |
| accesspressthemes | everest_timeline_lite | 1.1.1 | cpe:2.3:a:accesspressthemes:everest_timeline_lite:1.1.1:*:*:*:*:wordpress:*:* |
| accesspressthemes | fashstore | 1.2.1 | cpe:2.3:a:accesspressthemes:fashstore:1.2.1:*:*:*:*:wordpress:*:* |
| accesspressthemes | form_store_to_db | 1.0.9 | cpe:2.3:a:accesspressthemes:form_store_to_db:1.0.9:*:*:*:*:wordpress:*:* |
| accesspressthemes | fotography | 2.4.0 | cpe:2.3:a:accesspressthemes:fotography:2.4.0:*:*:*:*:wordpress:*:* |
| accesspressthemes | gaga_corp | 1.0.8 | cpe:2.3:a:accesspressthemes:gaga_corp:1.0.8:*:*:*:*:wordpress:*:* |
| accesspressthemes | gaga_lite | 1.4.2 | cpe:2.3:a:accesspressthemes:gaga_lite:1.4.2:*:*:*:*:wordpress:*:* |
| accesspressthemes | inline_call_to_action_builder_lite | 1.1.0 | cpe:2.3:a:accesspressthemes:inline_call_to_action_builder_lite:1.1.0:*:*:*:*:wordpress:*:* |
| accesspressthemes | mcontact_button | < 2.0.7 | cpe:2.3:a:accesspressthemes:mcontact_button:*:*:*:*:*:wordpress:*:* |
| accesspressthemes | one-paze | 2.2.8 | cpe:2.3:a:accesspressthemes:one-paze:2.2.8:*:*:*:*:wordpress:*:* |
| accesspressthemes | parallax_blog | 3.1.1574941215 | cpe:2.3:a:accesspressthemes:parallax_blog:3.1.1574941215:*:*:*:*:wordpress:*:* |
| accesspressthemes | parallaxsome | 1.3.6 | cpe:2.3:a:accesspressthemes:parallaxsome:1.3.6:*:*:*:*:wordpress:*:* |
| accesspressthemes | pi_button | 3.3.3 | cpe:2.3:a:accesspressthemes:pi_button:3.3.3:*:*:*:*:wordpress:*:* |
| accesspressthemes | product_slider_for_woocommerce_lite | 1.1.5 | cpe:2.3:a:accesspressthemes:product_slider_for_woocommerce_lite:1.1.5:*:*:*:*:wordpress:*:* |
| accesspressthemes | punte | 1.1.2 | cpe:2.3:a:accesspressthemes:punte:1.1.2:*:*:*:*:wordpress:*:* |
| accesspressthemes | revolve | 1.3.1 | cpe:2.3:a:accesspressthemes:revolve:1.3.1:*:*:*:*:wordpress:*:* |
| accesspressthemes | ripple | 1.2.0 | cpe:2.3:a:accesspressthemes:ripple:1.2.0:*:*:*:*:wordpress:*:* |
| accesspressthemes | scrollme | 2.1.0 | cpe:2.3:a:accesspressthemes:scrollme:2.1.0:*:*:*:*:wordpress:*:* |
| accesspressthemes | smart_logo_showcase_lite | 1.1.7 | cpe:2.3:a:accesspressthemes:smart_logo_showcase_lite:1.1.7:*:*:*:*:wordpress:*:* |
| accesspressthemes | smart_scroll_posts | 2.0.8 | cpe:2.3:a:accesspressthemes:smart_scroll_posts:2.0.8:*:*:*:*:wordpress:*:* |
| accesspressthemes | smart_scroll_to_top_lite | 1.0.3 | cpe:2.3:a:accesspressthemes:smart_scroll_to_top_lite:1.0.3:*:*:*:*:wordpress:*:* |
| accesspressthemes | social_auto_poster | 2.1.3 | cpe:2.3:a:accesspressthemes:social_auto_poster:2.1.3:*:*:*:*:wordpress:*:* |
| accesspressthemes | social_review | < 1.0.9 | cpe:2.3:a:accesspressthemes:social_review:*:*:*:*:*:wordpress:*:* |
| accesspressthemes | sportsmag | 1.2.1 | cpe:2.3:a:accesspressthemes:sportsmag:1.2.1:*:*:*:*:wordpress:*:* |
| accesspressthemes | storevilla | 1.4.1 | cpe:2.3:a:accesspressthemes:storevilla:1.4.1:*:*:*:*:wordpress:*:* |
| accesspressthemes | swing_lite | 1.1.9 | cpe:2.3:a:accesspressthemes:swing_lite:1.1.9:*:*:*:*:wordpress:*:* |
| accesspressthemes | tauto_poster | 1.4.5 | cpe:2.3:a:accesspressthemes:tauto_poster:1.4.5:*:*:*:*:wordpress:*:* |
| accesspressthemes | the_launcher | 1.3.2 | cpe:2.3:a:accesspressthemes:the_launcher:1.3.2:*:*:*:*:wordpress:*:* |
| accesspressthemes | the_monday | 1.4.1 | cpe:2.3:a:accesspressthemes:the_monday:1.4.1:*:*:*:*:wordpress:*:* |
| accesspressthemes | total_gdpr_compliance_lite | 1.0.4 | cpe:2.3:a:accesspressthemes:total_gdpr_compliance_lite:1.0.4:*:*:*:*:wordpress:*:* |
| accesspressthemes | total_team_lite | 1.1.1 | cpe:2.3:a:accesspressthemes:total_team_lite:1.1.1:*:*:*:*:wordpress:*:* |
| accesspressthemes | ultimate-form-builder-lite | 1.5.0 | cpe:2.3:a:accesspressthemes:ultimate-form-builder-lite:1.5.0:*:*:*:*:wordpress:*:* |
| accesspressthemes | ultimate_author_box_lite | 1.1.2 | cpe:2.3:a:accesspressthemes:ultimate_author_box_lite:1.1.2:*:*:*:*:wordpress:*:* |
| accesspressthemes | uncode_lite | 1.3.1 | cpe:2.3:a:accesspressthemes:uncode_lite:1.3.1:*:*:*:*:wordpress:*:* |
| accesspressthemes | unicon_lite | 1.2.6 | cpe:2.3:a:accesspressthemes:unicon_lite:1.2.6:*:*:*:*:wordpress:*:* |
| accesspressthemes | vmag | 1.2.7 | cpe:2.3:a:accesspressthemes:vmag:1.2.7:*:*:*:*:wordpress:*:* |
| accesspressthemes | vmagazine_lite | 1.3.5 | cpe:2.3:a:accesspressthemes:vmagazine_lite:1.3.5:*:*:*:*:wordpress:*:* |
| accesspressthemes | vmagazine_news | 1.0.5 | cpe:2.3:a:accesspressthemes:vmagazine_news:1.0.5:*:*:*:*:wordpress:*:* |
| accesspressthemes | wp_1_slider | 1.2.9 | cpe:2.3:a:accesspressthemes:wp_1_slider:1.2.9:*:*:*:*:wordpress:*:* |
| URL | Tags |
|---|---|
| https://jetpack.com/2022/01/18/backdoor-found-in-themes-and-plugins-from-accesspress-themes/ | Exploit Third Party Advisory |
| https://wpscan.com/vulnerability/9c76bada-fa32-4c2f-9855-d0efd1e63eff | Exploit Third Party Advisory |