S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2017-17059 Scanner

CVE-2017-17059 scanner - Cross-Site Scripting (XSS) vulnerability in amtyThumb plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.8k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2017-17059
6.1
CVSS

XSS exists in the amtyThumb amty-thumb-recent-post (aka amtyThumb posts or wp-thumb-post) plugin 8.1.3 for WordPress via the query string to amtyThumbPostsAdminPg.php.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 5, 2026View on NVD →
Detail

The amtyThumb plugin for WordPress is a tool used to display featured images in a widget format on a website's homepage. The plugin allows website developers to customize the display of their images with various sizes, labels, and other features. With the amtyThumb plugin, users can create a sleek and organized layout for their website's featured images.

However, the amtyThumb plugin has been found to have a major vulnerability: CVE-2017-17059. This vulnerability exists in the amty-thumb-recent-post version 8.1.3 plugin for WordPress. The vulnerability allows an attacker to inject malicious code into the plugin through a query string placed in the amtyThumbPostsAdminPg.php file.

The exploitation of this vulnerability could lead to the complete takeover of a website. Attackers may use the vulnerability to execute code remotely and potentially access sensitive information on a website, including user data. This vulnerability is particularly dangerous, as it can occur even if the attacker does not have any user credentials.

Thanks to the pro features of the s4e.io platform, website owners and developers can easily and quickly learn about vulnerabilities in their digital assets. By utilizing the platform's services, website owners can protect their websites from both known and unknown vulnerabilities. Overall, website security is critical, and the potential risks associated with a vulnerable plugin should never be overlooked.

 

REFERENCES

Solution Advice

Website developers must take precautions to protect their websites from this vulnerability. One way to do this is to update the plugin to its most recent version, which fixes the vulnerability. Secondly, web developers can take the following precautions:

  • Remove the amtyThumb plugin if it is not necessary for the website's functioning
  • Use a website scanner tool to detect and report vulnerable plugins
  • Set up access control lists and permissions on website files to prevent unwanted access
  • Use a web application firewall (WAF) to detect and block malicious attacks
  • Regularly update all installed plugins to their most recent and supported versions.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2017-17059 scanner - Cross-Site Scripting (XSS) vulnerability in amtyThumb plugin for WordPress | S4E