Files
CVEs-PoC/2021/CVE-2021-24867.md
T
2025-09-29 21:09:30 +02:00

188 lines
18 KiB
Markdown

### [CVE-2021-24867](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-24867)
![](https://img.shields.io/static/v1?label=Product&message=AP%20Companion&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=AccessPress%20Custom%20CSS&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=AccessPress%20Custom%20Post%20Type&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=AccessPress%20Parallax&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=AccessPress%20Root&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=AccessPress%20Social%20Counter&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=AccessPress%20Social%20Icons&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=AccessPress%20Social%20Login%20Lite%20%E2%80%93%20Social%20Login%20WordPress%20Plugin&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=AccessPress%20Social%20Share&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=AccessPress%20Staple&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=AccessPress%20Store&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=AccessPress%20iFeeds&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Accesspress%20Basic&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Accesspress%20Lite&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Accesspress%20Mag&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Agency%20Lite&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Aplite&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Badge%20Designer%20Lite%20For%20WooCommerce&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Beautiful%20FAQ%20Plugin%20for%20WordPress%20%E2%80%93%20Everest%20FAQ%20Manager%20Lite&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Beautiful%20Stat%20Counter%20Plugin%20for%20WordPress%20%E2%80%93%20Everest%20Counter%20Lite&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Bingle&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Bloger&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=CTA%20plugin%20for%20WordPress%20%E2%80%93%20Easy%20Side%20Tab&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Comments%20Disable%20%E2%80%93%20AccessPress&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Construction%20Lite&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Contact%20Form%20for%20WordPress%20%E2%80%93%20Ultimate%20Form%20Builder%20Lite&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Cookie%20Notification%20Plugin%20for%20WordPress%20%E2%80%93%20WP%20Cookie%20User%20Info&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Doko&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Easiest%20Contact%20Form%20for%20WordPress%20%E2%80%93%20AP%20Contact%20Form&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Effectively%20Add%20%26%20Customize%20Free%20Icons%20For%20WordPress%20Menus%20%E2%80%93%20WP%20Menu%20Icons%20Lite&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Enlighten&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Everest%20GPlaces%20Business%20Reviews&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Everest%20Review%20Lite%20%E2%80%93%20User%2FAdmin%20review%20plugin%20for%20WordPress&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=FashStore&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Faster%20and%20Easier%20scroll%20to%20Top%20Plugin%20for%20WordPress%20%E2%80%93%20Smart%20Scroll%20to%20Top%20Lite&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Form%20Store%20to%20DB&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=FotoGraphy&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Free%20Responsive%20Post%2FArticle%20Author%20Section%20Plugin%20for%20WordPress%20%E2%80%93%20Ultimate%20Author%20Box%20Lite&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Free%20Responsive%20Tab%20Plugin%20For%20WordPress%20%E2%80%93%20Everest%20Tab%20Lite&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Free%20WordPress%20Plugin%20To%20Display%20Like%2FDislike%20Comment%20Rating%20%E2%80%93%20Everest%20Comment%20Rating%20Lite&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Frontend%20Post%20WordPress%20Plugin%20%E2%80%93%20AccessPress%20Anonymous%20Post&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Gaga%20Corp&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Gaga%20Lite&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Inline%20Call%20To%20Action%20Builder%20Lite%20%E2%80%93%20Free%20Call%20To%20Action%20Layer%20Plugin%20for%20WordPress&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MContact%20Button&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Mega%20Menu%20Plugin%20for%20WordPress%20%E2%80%93%20AP%20Mega%20Menu&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=One%20Paze&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=PI%20Button&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=ParallaxSome&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Plugin%20to%20Manage%20%2F%20Design%20WordPress%20Blog%20%E2%80%93%20WP%20Blog%20Manager%20Lite&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Pricing%20Table%20Builder%20%E2%80%93%20AP%20Pricing%20Tables%20Lite&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Product%20Slider%20For%20WooCommerce%20Lite&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Punte&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Responsive%20Clients%20Logo%20Gallery%20Plugin%20for%20WordPress%20%E2%80%93%20Smart%20Logo%20Showcase%20Lite&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Responsive%20Media%20Gallery%20Plugin%20for%20WordPress%20%E2%80%93%20Everest%20Gallery%20Lite&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Responsive%20Notification%20Bar%20Plugin%20for%20WordPress%20%E2%80%93%20Apex%20Notification%20Bar%20Lite&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Responsive%20Products%20Showcase%20Listing%20for%20WordPress%20%20%E2%80%93%20WP%20Product%20Gallery%20Lite&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Responsive%20WordPress%20Timeline%20Plugin%20%E2%80%93%20Everest%20Timeline%20Lite&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Revolve&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Ripple&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=ScrollMe&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Smart%20Scroll%20Posts%20for%20WordPress&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Smartest%20Way%20To%20Design%20%26%20Customize%20WordPress%20Comments%20%26%20Comment%20Form%20%E2%80%93%20WP%20Comment%20Designer%20Lite&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Social%20Auto%20Poster&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Social%20Review&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=SportsMag&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=StoreVilla&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Swing%20Lite&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=TAuto%20Poster&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Testimonial%20WordPress%20Plugin%20%E2%80%93%20AP%20Custom%20Testimonial&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=The%20Easiest%20WordPress%20Media%20Manager%20Plugin%20%E2%80%93%20WP%20Media%20Manager%20Lite&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=The%20Launcher&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=The%20Monday&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Total%20GDPR%20Compliance%20Lite%20%E2%80%93%20WordPress%20Plugin%20for%20GDPR%20Compatibility&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Total%20Team%20Lite%20%E2%80%93%20Responsive%20Team%20Manager%20%2F%20Showcase%20Plugin%20for%20WordPress&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Ultimate%20Coming%20Soon%2C%20Maintenance%20Mode%20Plugin%20for%20WordPress%20%E2%80%93%20Everest%20Coming%20Soon%20Lite&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Uncode%20Lite&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Unicon%20Lite&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=VMag&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=VMagazine%20Lite&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Vmagazine%20News&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=WP%20Floating%20Menu%20%E2%80%93%20One%20page%20navigator%2C%20sticky%20menu%20for%20WordPress&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=WP%20Popup%20Banners&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=WP%20Popup%20Lite%20%E2%80%93%20Responsive%20popup%20plugin%20for%20WordPress&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=WP%20TFeed&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=WordPress%20Backend%20Customizer%20%E2%80%93%20Everest%20Admin%20Theme%20Lite&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=WordPress%20Slider%20Plugin%20%E2%80%93%20WP%201%20Slider&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Zigcy%20Baby&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Zigcy%20Cosmetics&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Zigcy%20Lite&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=accessbuddy&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=accesspress-ray&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=parallax-blog&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=1.0.0%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=1.0.27%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=1.0.3%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=1.0.4%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=1.0.5%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=1.0.6%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=1.0.7%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=1.0.8%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=1.0.9%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=1.1.0%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=1.1.1%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=1.1.2%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=1.1.3%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=1.1.5%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=1.1.6%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=1.1.7%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=1.1.8%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=1.1.9%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=1.19.5%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=1.2.0%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=1.2.1%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=1.2.3%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=1.2.4%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=1.2.5%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=1.2.6%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=1.2.7%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=1.2.9%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=1.3.0%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=1.3.1%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=1.3.2%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=1.3.5%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=1.3.6%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=1.4.1%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=1.4.2%201.0.8%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=1.4.4%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=1.4.5%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=1.4.6%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=1.4.7%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=1.5.0%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=1.5.1%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=1.6.7%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=1.6.8%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=1.8.2%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=1.8.3%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=1.9.1%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=1.9.2%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.0.0%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.0.1%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.0.2%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.0.3%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.0.4%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.0.5%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.0.7%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.0.8%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.0.9%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.1.0%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.1.3%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.1.4%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.2.8%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.4.0%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.4.9%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.5%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.6.5%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.8.0%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.8.1%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.92%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=3.0.5%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=3.0.6%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=3.1.1574941215%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=3.2.1%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=3.3.3%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=3.3.4%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=3.4.7%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=3.4.8%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=4.0.3%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=4.0.4%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=4.5%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=4.5.5%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=4.5.6%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-912%20Hidden%20Functionality&color=brightgreen)
### Description
Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/20142995/nuclei-templates