S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-39322 Scanner

CVE-2021-39322 scanner - Cross-Site Scripting (XSS) vulnerability in Easy Social Icons plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.2k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-39322
6.1
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.

The Easy Social Icons plugin <= 3.0.8 for WordPress echoes out the raw value of `$_SERVER['PHP_SELF']` in its main file. On certain configurations including Apache+modPHP this makes it possible to use it to perform a reflected Cross-Site Scripting attack by injecting malicious code in the request path.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
Easy Social Iconsby cybernetikz
3.0.8
Updated Aug 21, 2026View on NVD →
Detail

The Easy Social Icons plugin for WordPress is a popular plugin used by website owners to display social media icons on their pages. It allows users to easily add links to their Facebook, Twitter, Instagram, and other social media profiles. With over 100,000 active installations, it has become a go-to plugin for many bloggers and website owners.

Recently, a vulnerability in the plugin, labeled CVE-2021-39322, was detected. This vulnerability occurs when the plugin echoes out the raw value of `$_SERVER['PHP_SELF']` in its main file, making it possible for attackers to inject malicious code into the request path. This flaw can be exploited by attackers to perform a reflected Cross-Site Scripting (XSS) attack on vulnerable websites.

When this vulnerability is exploited, an attacker can inject malicious code into the website. This malicious code can then execute in the browser of website visitors when they access the compromised page. Attackers can use this vulnerability to steal sensitive information, such as login credentials or financial information, from unsuspecting visitors. This can lead to reputational damage, regulatory fines, and even litigation for affected organizations.

Thanks to the pro features of the s4e.io platform, website owners can easily and quickly learn about vulnerabilities in their digital assets. Our platform provides continuous monitoring and automated vulnerability scanning to help organizations stay on top of emerging threats. With our comprehensive, user-friendly reports, website owners can quickly identify and remediate vulnerabilities before they can be exploited by attackers. Protect your digital assets today with s4e.io.

 

REFERENCES

Solution Advice

To protect against this vulnerability, website owners can take the following precautions:

  • Update the Easy Social Icons plugin to the latest version (3.0.9 at the time of writing).
  • Use a Web Application Firewall (WAF) to filter out malicious requests.
  • Implement strong input validation checks on user input.
  • Use secure coding practices to avoid introducing vulnerabilities in code.
  • Establish a security testing program, including vulnerability assessments and penetration testing, to identify and address security holes in a timely manner.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.