plugin

Accesspress Social Icons Vulnerabilities

10 known security issues reported for the Accesspress Social Icons WordPress plugin. Most recent disclosed Feb 21, 2022.

2 high 1 medium

Running Accesspress Social Icons on your site? Check whether your installed version is affected.

Scan your site free

AccessPress Social Icons [accesspress-social-icons] < 1.8.3 (closed)

unknown

[en] Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confus...

Affected:
up to 1.8.3
Fixed in:
1.8.3
Disclosed:
Feb 21, 2022

CVE-2021-24867 on NVD →

AccessPress Social Icons 1.8.2 - Backdoor

high

The AccessPress Social Icons plugin for WordPress contains a backdoor when downloaded directly from the AccessPress site in version 1.8.2. This allows attackers to gain full control of a site with the plugin installed.

CVSS:
7.5
Affected:
1.8.2 – 1.8.2
Fixed in:
1.8.3
Disclosed:
Jan 18, 2022

AccessPress Social Icons [accesspress-social-icons] < 1.8.3 (closed)

unknown

The AccessPress Social Icons plugin for WordPress contains a backdoor when downloaded directly from the AccessPress site in version 1.8.2. This allows attackers to gain full control of a site with the plugin installed.

Affected:
up to 1.8.3
Fixed in:
1.8.3
Disclosed:
Jan 18, 2022

AccessPress Social Icons [accesspress-social-icons] < 1.8.1 (closed)

unknown

[en] Unvalidated input in the AccessPress Social Icons plugin, versions before 1.8.1, did not sanitise its widget attribute, allowing accounts with post permission, such as author, to perform SQL injections.

Affected:
up to 1.8.1
Fixed in:
1.8.1
Disclosed:
Mar 18, 2021

CVE-2021-24143 on NVD →

AccessPress Social Icons [accesspress-social-icons] < 1.8.1 (closed)

unknown

Authenticated SQL Injection (SQLi) vulnerability found by Nguyen Khang in WordPress Accesspress Social Icons plugin (version <= 1.8.0).

Affected:
up to 1.8.1
Fixed in:
1.8.1
Disclosed:
Nov 28, 2020

AccessPress Social Icons <= 1.8.0 - Author+ SQL Injection

high

Unvalidated input in the AccessPress Social Icons plugin, versions before 1.8.1, did not sanitise its widget attribute, allowing accounts with post permission, such as author, to perform SQL injections.

CVSS:
8.8
Affected:
up to 1.8.1
Fixed in:
1.8.1
Disclosed:
Nov 2, 2020

CVE-2021-24143 on NVD →

AccessPress Social Icons [accesspress-social-icons] < 1.6.7 (closed)

unknown

WordPress plugin AccessPress Social Icons version 1.6.6 (and earlier versions) suffers from Multiple SQL injection vulnerabilities. Patched version 1.6.7 already available. Update plugin to the latest available version (at least 1.6.7).

Affected:
up to 1.6.7
Fixed in:
1.6.7
Disclosed:
Apr 20, 2017

AccessPress Social Icons <= 1.6.6 - Cross-Site Scripting

medium

The AccessPress Social Icons plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.6.6 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
6.1
Affected:
up to 1.6.6
Fixed in:
1.6.7
Disclosed:
Apr 19, 2017

AccessPress Social Icons [accesspress-social-icons] < 1.6.7 (closed)

unknown

The AccessPress Social Icons plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.6.6 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

Affected:
up to 1.6.7
Fixed in:
1.6.7
Disclosed:
Apr 19, 2017

AccessPress Social Icons [accesspress-social-icons] < 1.6.8 (closed)

unknown

During the security analysis, ThunderScan discovered SQL injection vulnerabilities in AccessPress Social Icons WordPress plugin. The easiest way to reproduce the vulnerability is to visit the provided URL while being logged in as administrator or another user that is authorized to access the plugin settings page. Any u...

Affected:
up to 1.6.8
Fixed in:
1.6.8

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database