S4E just found a high-severity finding from ssl sweet32 vulnerability checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Feb 9, 2026

CVE-2024-13225 Scanner

CVE-2024-13225 Scanner - Cross-Site Scripting (XSS) vulnerability in ECT Home Page Products

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.7k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-13225
6.1
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.

The ECT Home Page Products WordPress plugin through 1.9 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
ECT Home Page Products
0
Updated Aug 22, 2026View on NVD →
Detail

ECT Home Page Products is a WordPress plugin developed by etemplates. It is designed to help users manage and showcase products on their WordPress websites. This plugin is especially useful for small businesses and entrepreneurs looking to enhance their online presence. Users primarily employ it to create engaging homepages and product displays. Offering easy integration with WordPress, it aims to enhance user engagement and improve online sales. However, like many plugins, it requires regular updates to ensure security and smooth functionality.

The vulnerability in ECT Home Page Products involves a reflected Cross-Site Scripting (XSS) flaw. This occurs due to the lack of proper sanitization and escaping of input parameters before they are rendered in the browser. Attackers can exploit this XSS vulnerability to inject malicious scripts into web pages viewed by high privilege users. The potential impact includes session hijacking, identity theft, and potentially compromising admin accounts. Attackers rely on tricking victims into visiting specially crafted web pages to leverage this vulnerability.

The technical details of this XSS vulnerability revolve around inadequate input validation on a specific page within the plugin's admin panel. A crafted GET request to the vulnerable endpoint can trigger the vulnerability when script tags are included in a parameter. This unvalidated input is echoed back in the HTML response, allowing the execution of arbitrary JavaScript in the browser. The vulnerable endpoint resides within the admin interface, which compounds the risk by targeting users with higher privileges. Successful exploitation depends on user interaction, as victims must visit the attacker's crafted link.

If exploited by malicious actors, this vulnerability can lead to session hijacking and disclosure of sensitive information. Specifically, attackers might manipulate user sessions to access and control admin functionalities. Further, any personal or transactional data stored within affected sessions could be at risk. Persistent exploitation can destabilize the integrity of the web application's security framework. Additionally, trust in affected websites could diminish if the vulnerability is publicly exploited.

REFERENCES

Solution Advice
  • Update to the latest version of the ECT Home Page Products plugin where the XSS vulnerability is fixed.
  • Consider implementing additional input validation and output escaping mechanisms on affected pages.
  • Regularly educate users, especially high privilege users, about the risks of interacting with suspicious links.
  • Consistently monitor security advisories for plugins in use and act promptly on vulnerability disclosures.
  • Apply a web application firewall (WAF) to detect and block potential XSS attacks.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.