AccessPress Anonymous Post <= 2.8.4 - Authenticated (Contributor+) Arbitrary Redirect
medium
The AccessPress Anonymous Post plugin for WordPress is vulnerable to Arbitrary Redirect in versions up to, and including, 2.8.4. This is due to insufficient validation on one of the attributes for one of its shortcodes. This makes it possible for authenticated attackers, with contributor-level access, to redirect users...
- CVSS:
- 4.3
- Affected:
- up to 2.8.4
- Fix:
- No patched version reported
- Disclosed:
- May 11, 2023
CVE-2022-4946 on NVD →
AccessPress Anonymous Post = 2.8.0 - Backdoored
high
Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion
- CVSS:
- 8.8
- Affected:
- 2.8.0 – 2.8.0
- Fixed in:
- 2.8.1
- Disclosed:
- Oct 13, 2021
CVE-2021-24867 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database