S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-24838 Scanner

CVE-2021-24838 scanner - Open Redirect vulnerability in AnyComment plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.9k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-24838
6.1
CVSS

The AnyComment WordPress plugin before 0.3.5 has an API endpoint which passes user input via the redirect parameter to the wp_redirect() function without being validated first, leading to an Open Redirect issue, which according to the vendor, is a feature.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
AnyComment
AFFECTED< 0.3.5SAFE ✓≥ 0.3.5
Updated Aug 21, 2026View on NVD →
Detail

AnyComment is a popular WordPress plugin designed to facilitate interaction and communication between website users and administrators. Users can submit comments, reviews, ratings, and feedback on websites running AnyComment, while administrators can reply to these comments and engage with their audience. The plugin aims to improve user engagement on WordPress websites and enhance the user experience on these platforms.

However, security researchers have recently identified a major vulnerability in AnyComment, known as CVE-2021-24838. This vulnerability arises from an API endpoint within the plugin that allows user input to be passed via the redirect parameter to the wp_redirect() function without adequate validation. This means that attackers can exploit the vulnerability to redirect users to malicious websites and compromise their security.

The exploitation of CVE-2021-24838 can have severe consequences for the security of WordPress websites that use AnyComment. Attackers can easily craft URLs that redirect users to phishing sites or websites with malware, leading to the installation of harmful software on the victim's computer. This can result in the loss of sensitive data or the compromise of the entire WordPress site, putting both users and administrators at risk.

Overall, the discovery of CVE-2021-24838 highlights the importance of maintaining the security of WordPress websites, especially for those that rely on third-party plugins. By utilizing pro features of the s4e.io platform, users can quickly detect and address vulnerabilities in their digital assets, including WordPress websites running AnyComment. With advanced security solutions at their fingertips, website owners can ensure that their online presence remains safe, secure, and trusted by their audiences.

 

REFERENCES

Solution Advice

To protect against this vulnerability, website administrators can take a few simple but effective precautions:

  • Update the AnyComment plugin to version 0.3.5 or later, which includes a fix for CVE-2021-24838.
  • Configure any website firewalls or security plugins to block requests containing suspicious URL parameters.
  • Educate users on the risks of clicking on unknown links and advise them to only visit reputable websites.
  • Enable Two-Factor Authentication (2FA) on WordPress accounts to prevent unauthorized access.
  • Monitor website logs and traffic for signs of suspicious activity.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.