S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Feb 23, 2024

CVE-2021-24956 Scanner

CVE-2021-24956 scanner - Cross-Site Scripting (XSS) vulnerability in Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.4k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-24956
6.1
CVSS

The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.8.7 does not sanitise and escape the b2sShowByDate parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting issue

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Blog2Social: Social Media Auto Post & Scheduler
AFFECTED< 6.8.7SAFE ✓≥ 6.8.7
Updated Aug 21, 2026View on NVD →
Detail

Vulnerability Overview

CVE-2021-24956 enables attackers to inject malicious scripts into the web pages, potentially leading to unauthorized actions being performed under the guise of a legitimate user.

Vulnerability Details

The flaw is specifically found in the handling of the 'b2sShowByDate' parameter within the admin dashboard of the Blog2Social plugin. Due to insufficient sanitization, attackers can inject JavaScript code that is executed in the context of the admin's browser session.

Possible Effects

Exploiting this vulnerability can result in:

  • Session hijacking and impersonation of administrative users.
  • Theft of sensitive information from the browser session.
  • Defacement of the website or redirection to malicious sites.

Why Choose S4E

S4E offers a robust platform for detecting and managing vulnerabilities like CVE-2021-24956. Our tools provide:

  • Detailed vulnerability assessments and actionable insights.
  • Real-time alerts for new vulnerabilities affecting your digital assets.
  • Expert support for remediation strategies to enhance your cybersecurity posture. Secure your online presence with S4E and stay ahead of cyber threats.

References

Solution Advice
  • Update the Plugin: Immediately upgrade to Blog2Social version 6.8.7 or newer.
  • Use Content Security Policy (CSP): Implement CSP headers to reduce the risk of XSS attacks.
  • Regular Security Audits: Conduct periodic reviews of installed plugins and themes for potential vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-24956 scanner - Cross-Site Scripting (XSS) vulnerability in Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress | S4E