Accesspressthemes develops a modestly represented portfolio of WordPress plugins and themes spanning utilities such as demo importers, testimonial widgets, menu builders, and construction-focused templates. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a moderate tendency toward public exploit availability, clustering around common web-application weaknesses including SQL injection, cross-site scripting, CSRF, and unrestricted file uploads that are characteristic of plugin-based extensibility. Defenders should treat this vendor's advisories as high-priority for any WordPress installations that bundle its components; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Accesspressthemes over time
Signals from CVEs in this vendor scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-16949CRITICAL An issue was discovered in the AccessKeys AccessPress Anonymous Post Pro plugin through 3.1.9 for WordPress. Improper input sanitization allows the attacker to override the setting | Dec 19, 2017 | 9.8 | 50 | NO | YES |
CVE-2021-24867CRITICAL Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the v | Feb 21, 2022 | 9.8 | 40 | NO | NO |
CVE-2017-15919CRITICAL The ultimate-form-builder-lite plugin before 1.3.7 for WordPress has SQL Injection, with resultant PHP Object Injection, via wp-admin/admin-ajax.php. | Oct 26, 2017 | 9.8 | 30 | NO | NO |
CVE-2021-39317HIGH A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to malicious file uploads via the plugin_offline_installer AJAX action due to a missi | Oct 11, 2021 | 8.8 | 28 | NO | NO |
CVE-2021-24143HIGH Unvalidated input in the AccessPress Social Icons plugin, versions before 1.8.1, did not sanitise its widget attribute, allowing accounts with post permission, such as author, to p | Mar 18, 2021 | 8.8 | 26 | NO | NO |
CVE-2022-23976HIGH Cross-Site Request Forgery (CSRF) in Access Demo Importer <= 1.0.7 on WordPress allows an attacker to reset all data (posts / pages / media). | Apr 18, 2022 | 8.1 | 25 | NO | NO |
CVE-2023-26532HIGH Cross-Site Request Forgery (CSRF) vulnerability in AccessPress Themes Social Auto Poster plugin <= 2.1.4 versions. | Nov 22, 2023 | 8.8 | 24 | NO | NO |
CVE-2023-26518HIGH Cross-Site Request Forgery (CSRF) vulnerability in AccessPress Themes WP TFeed plugin <= 1.6.9 versions. | Nov 13, 2023 | 8.8 | 24 | NO | NO |
CVE-2022-23911HIGH The Testimonial WordPress Plugin WordPress plugin before 1.4.7 does not validate and escape the id parameter before using it in a SQL statement when retrieving a testimonial to edi | Feb 28, 2022 | 7.2 | 24 | NO | NO |
CVE-2021-24858HIGH The Cookie Notification Plugin for WordPress plugin before 1.0.9 does not sanitise or escape the id GET parameter before using it in a SQL statement, when retrieving the setting to | Jan 24, 2022 | 7.2 | 24 | NO | NO |
Signals from CVEs in this vendor scope (18 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Accesspressthemes.
Media articles that mention a CVE ID that affects a product developed by Accesspressthemes — matched by CVE ID, not by vendor name.