S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-24226 Scanner

CVE-2021-24226 scanner - Information Disclosure vulnerability in AccessAlly

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.8k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-24226
7.5
CVSS

In the AccessAlly WordPress plugin before 3.5.7, the file "resource/frontend/product/product-shortcode.php" responsible for the [accessally_order_form] shortcode is dumping serialize($_SERVER), which contains all environment variables. The leakage occurs on all public facing pages containing the [accessally_order_form] shortcode, no login or administrator role is required.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
AccessAlly
AFFECTED< 3.5.6*SAFE ✓≥ 3.5.6*
Updated Aug 21, 2026View on NVD →
Detail

AccessAlly is a WordPress plugin designed to help businesses and entrepreneurs sell and deliver online courses, memberships, and other digital products. It integrates with popular email marketing and payment systems, allowing users to create powerful and flexible order forms, membership portals, and sales funnels. AccessAlly provides customizable templates and drag-and-drop design tools, making it relatively easy for non-technical users to create professional-looking pages.

CVE-2021-24226 is a vulnerability that affects AccessAlly before version 3.5.7. The issue arises from a file named "resource/frontend/product/product-shortcode.php," which is used to process the [accessally_order_form] shortcode. This file inadvertently exposes the $_SERVER variable, which contains a variety of sensitive information about the server environment, including IP addresses, file paths, system settings, and more. As a result, an attacker could potentially access this information and use it to launch further attacks or exploit other vulnerabilities.

If exploited, the CVE-2021-24226 vulnerability could lead to a variety of security issues, including data breaches, website defacement, or unauthorized access to sensitive information. Attackers could potentially use the leaked information to launch other attacks, such as SQL injection or cross-site scripting. In addition, the exposure of server information could aid attackers in identifying weaknesses in the server environment, potentially leading to further vulnerabilities.

s4e.io is a powerful and easy-to-use platform for identifying and mitigating vulnerabilities in digital assets. With advanced scanning capabilities and a comprehensive database of known vulnerabilities, s4e.io can quickly uncover potential issues and offer recommended solutions. By using s4e.io, AccessAlly users can stay on top of emerging threats and protect their online businesses with confidence.

 

REFERENCES

Solution Advice

To protect against CVE-2021-24226 and other vulnerabilities, AccessAlly users should take the following precautions:

  • Update to the latest version of AccessAlly, which includes a fix for CVE-2021-24226.
  • Regularly check for and apply software updates for WordPress, themes, and plugins.
  • Use strong, unique passwords and enable two-factor authentication for all user accounts.
  • Monitor server logs and network traffic for signs of suspicious activity or unauthorized access.
  • Consider using a web application firewall or other security plugins to supplement AccessAlly's built-in security features.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.