S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2021-24285 Scanner

CVE-2021-24285 scanner - SQL Injection vulnerability in Car Seller Auto Classifieds Script

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.6k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-24285
9.8
CVSS

The request_list_request AJAX call of the Car Seller - Auto Classifieds Script WordPress plugin through 2.1.0, available to both authenticated and unauthenticated users, does not sanitise, validate or escape the order_id POST parameter before using it in a SQL statement, leading to a SQL Injection issue.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Car Seller - Auto Classifieds Script
2.1.0
Updated Aug 21, 2026View on NVD →
Detail

Car Seller Auto Classifieds Script is a WordPress plugin that enables site owners to create a platform where they can sell automobiles. The plugin is designed to be user-friendly, intuitive, and easy to use. It comes with a range of features, including the ability to create custom categories, add custom fields, and set up a search filter.

Unfortunately, the plugin has been found to contain a critical vulnerability. CVE-2021-24285 is a SQL injection vulnerability that exists in the request_list_request AJAX call of the plugin. This vulnerability is present in both authenticated and unauthenticated contexts, and it arises because the plugin does not validate, sanitize or escape the order_id POST parameter before using it in a SQL statement.

When exploited, this vulnerability can allow an attacker to execute arbitrary SQL queries. This can lead to data leakage, data manipulation, and full system compromise. An attacker can steal sensitive information, compromise user accounts, and even take control of the entire WordPress installation, compromising the entire website.

At s4e.io, we provide users with the tools they need to stay on top of their website's security. With our pro features, users can quickly and easily learn about vulnerabilities in their digital assets. We offer comprehensive vulnerability scanning and reporting to help our clients stay ahead of the game. With s4e.io, you can be confident that your website is secure and protected from malicious attacks.

 

REFERENCES

Solution Advice

To protect against this vulnerability, site owners should take the following precautions:

  • Update the plugin to the latest version. - Apply all security patches as soon as they become available.
  • Monitor the site's logs and watch for any suspicious activity.
  • Use a web application firewall to filter out malicious requests.
  • Regularly audit the site for vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.