S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-24276 Scanner

CVE-2021-24276 scanner - Cross-Site Scripting (XSS) vulnerability in Contact Form by Supsystic

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-24276
6.1
CVSS

The Contact Form by Supsystic WordPress plugin before 1.7.15 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Contact Form by Supsysticby Supsystic
AFFECTED< 1.7.15SAFE ✓≥ 1.7.15
Updated Aug 21, 2026View on NVD →
Detail

The Contact Form by Supsystic is a WordPress plugin designed to create customizable contact forms for websites. This tool helps website owners to create and publish forms easily. With this plugin, users can set up a contact form with minimal knowledge of coding. Contact Form by Supsystic offers custom fields, allowing users to create forms that meet their specific needs, making it an effective tool for both personal and professional websites.

The CVE-2021-24276 vulnerability is a reflected Cross-Site Scripting (XSS) issue detected in Contact Form by Supsystic before version 1.7.15. As the plugin did not sanitize the tab parameter of its options page, an attacker could inject malicious code into the tab parameter, which would then be executed in the user's browser upon visiting the page. This vulnerability could be exploited by an attacker to steal sensitive user information such as cookies, session tokens, and personal details.

When exploited, the CVE-2021-24276 vulnerability could allow an attacker to bypass the security protocols of websites where the plugin is installed. Given the vast amount of sensitive data that passes through contact forms, an attacker could easily gain access to confidential information that can be used to carry out malicious activities such as identity theft, financial fraud, and other criminal activities. Once this vulnerability is exploited, it can be challenging to detect and mitigate the damage caused.

By using the pro features of S4E, you can easily and quickly learn about vulnerabilities affecting your digital assets. The platform offers comprehensive solutions such as website monitoring, vulnerability scanning, penetration testing, and cyber intelligence, which can help identify risks and safeguard your online presence. Take the necessary steps to protect your website and ensure your sensitive information remains secure.

 

REFERENCES

Solution Advice

To protect against this vulnerability, you can take these precautions:

  • Update the Contact Form by Supsystic to the latest version (1.7.15 or later).
  • Use a security plugin to scan your website regularly for vulnerabilities.
  • Enable automatic updates for WordPress themes and plugins.
  • Perform a security audit of your website to identify vulnerabilities.
  • Keep your website software up-to-date to ensure that it is not vulnerable to known exploits.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.