S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Feb 11, 2026

CVE-2024-13055 Scanner

CVE-2024-13055 Scanner - Cross-Site Scripting (XSS) vulnerability in Dyn Business Panel Plugin

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.2k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-13055
7.1
CVSShigh
Exploitable remotely over the internet · no authentication required · user interaction needed.

The Dyn Business Panel WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
Dyn Business Panel
0
Updated Sep 10, 2026View on NVD →
Detail

Dyn Business Panel Plugin is a component of the WordPress ecosystem, used predominantly by webmasters managing dynamic business websites. Designed to offer enhanced functionality, it simplifies business operations on WordPress through various user-friendly controls. Its usage spans across various sectors aiming to integrate business logic within their web presence. End-users of varying technical expertise rely on it for seamless business management, capitalizing on its customization features. As a plugin, it connects intricately with WordPress installations, providing critical business functionalities. However, like many extensions in the WordPress repository, it is susceptible to security vulnerabilities.

Cross-Site Scripting (XSS) vulnerabilities allow attackers to inject malicious scripts into web pages viewed by other users. This flaw in the Dyn Business Panel Plugin involves insufficient sanitization and escaping of input parameters. It enables unauthorized script execution within the context of high-privilege users, escalating potential threats rapidly. With users only needing to click on a crafted malicious link, the vulnerability becomes notably viable for exploitation. Once exploited, it could lead to unauthorized actions or data compromise. Its discovery underscores the importance of stringent input validation protocols in plugins.

Technical details of this vulnerability reveal that an endpoint related to client editing is notably exploitable. Parameters processed during the client editing phase lack appropriate input cleaning, snowballing into potentially harmful script execution. Attackers exploit this by crafting specific GET requests with script tags, leveraging unhandled user input. Manipulation of the parameter `dbp_client_id` showcases inadequate defensive measures against such input tampering. This enables persistent malicious script execution, hidden behind code interfacing layers like authentication routines. It highlights a critical oversight often found in similarly structured plugin systems.

If exploited, the vulnerability can significantly impact the confidentiality and integrity of user accounts. Attackers have the potential to hijack sessions, impersonate users, or steal sensitive data. High-level access may enable further exploitation within affected websites, leading to widespread compromise. Data theft becomes a tangible threat, especially with attackers gaining unauthorized access to business-transcending information. Furthermore, successful exploitation might facilitate the distribution of additional malicious payloads to other interacting users. Over time, such impacts can degrade trust in compromised websites or related services.

REFERENCES

Solution Advice
  • Update the Dyn Business Panel Plugin to the latest version where the vulnerability is patched.
  • Implement proper input sanitization and escaping to prevent similar vulnerabilities in the future.
  • Educate users to avoid clicking on untrusted and suspicious links.
  • Enable Content Security Policy (CSP) to restrict script execution on the website.
  • Regularly audit and test plugin security for emerging vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2024-13055 Scanner - Cross-Site Scripting (XSS) vulnerability in Dyn Business Panel Plugin | S4E