AccessPress Social Icons [accesspress-social-icons] < 1.8.3 (closed)
unknown
[en] Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confus...
- Affected:
- up to 1.8.3
- Fixed in:
- 1.8.3
- Disclosed:
- Feb 21, 2022
CVE-2021-24867 on NVD →
AccessPress Social Icons 1.8.2 - Backdoor
high
The AccessPress Social Icons plugin for WordPress contains a backdoor when downloaded directly from the AccessPress site in version 1.8.2. This allows attackers to gain full control of a site with the plugin installed.
- CVSS:
- 7.5
- Affected:
- 1.8.2 – 1.8.2
- Fixed in:
- 1.8.3
- Disclosed:
- Jan 18, 2022
AccessPress Social Icons [accesspress-social-icons] < 1.8.3 (closed)
unknown
The AccessPress Social Icons plugin for WordPress contains a backdoor when downloaded directly from the AccessPress site in version 1.8.2. This allows attackers to gain full control of a site with the plugin installed.
- Affected:
- up to 1.8.3
- Fixed in:
- 1.8.3
- Disclosed:
- Jan 18, 2022
AccessPress Social Icons [accesspress-social-icons] < 1.8.1 (closed)
unknown
[en] Unvalidated input in the AccessPress Social Icons plugin, versions before 1.8.1, did not sanitise its widget attribute, allowing accounts with post permission, such as author, to perform SQL injections.
- Affected:
- up to 1.8.1
- Fixed in:
- 1.8.1
- Disclosed:
- Mar 18, 2021
CVE-2021-24143 on NVD →
AccessPress Social Icons [accesspress-social-icons] < 1.8.1 (closed)
unknown
Authenticated SQL Injection (SQLi) vulnerability found by Nguyen Khang in WordPress Accesspress Social Icons plugin (version <= 1.8.0).
- Affected:
- up to 1.8.1
- Fixed in:
- 1.8.1
- Disclosed:
- Nov 28, 2020
AccessPress Social Icons <= 1.8.0 - Author+ SQL Injection
high
Unvalidated input in the AccessPress Social Icons plugin, versions before 1.8.1, did not sanitise its widget attribute, allowing accounts with post permission, such as author, to perform SQL injections.
- CVSS:
- 8.8
- Affected:
- up to 1.8.1
- Fixed in:
- 1.8.1
- Disclosed:
- Nov 2, 2020
CVE-2021-24143 on NVD →
AccessPress Social Icons [accesspress-social-icons] < 1.6.7 (closed)
unknown
WordPress plugin AccessPress Social Icons version 1.6.6 (and earlier versions) suffers from Multiple SQL injection vulnerabilities. Patched version 1.6.7 already available.
Update plugin to the latest available version (at least 1.6.7).
- Affected:
- up to 1.6.7
- Fixed in:
- 1.6.7
- Disclosed:
- Apr 20, 2017
AccessPress Social Icons <= 1.6.6 - Cross-Site Scripting
medium
The AccessPress Social Icons plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.6.6 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- CVSS:
- 6.1
- Affected:
- up to 1.6.6
- Fixed in:
- 1.6.7
- Disclosed:
- Apr 19, 2017
AccessPress Social Icons [accesspress-social-icons] < 1.6.7 (closed)
unknown
The AccessPress Social Icons plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.6.6 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- Affected:
- up to 1.6.7
- Fixed in:
- 1.6.7
- Disclosed:
- Apr 19, 2017
AccessPress Social Icons [accesspress-social-icons] < 1.6.8 (closed)
unknown
During the security analysis, ThunderScan discovered SQL injection vulnerabilities in AccessPress Social Icons WordPress plugin. The easiest way to reproduce the vulnerability is to visit the provided URL while being logged in as administrator or another user that is authorized to access the plugin settings page. Any u...
- Affected:
- up to 1.6.8
- Fixed in:
- 1.6.8
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database