S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-24389 Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in FoodBakery affects v. < 2.2.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.5k
Times Used
continuous scan runs
3.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-24389
6.1
CVSS

The WP Foodbakery WordPress plugin before 2.2, used in the FoodBakery WordPress theme before 2.2 did not properly sanitize the foodbakery_radius parameter before outputting it back in the response, leading to an unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
WP Foodbakeryby Chimpstudio
AFFECTED< 2.2SAFE ✓≥ 2.2
FoodBakeryby Chimpstudio
AFFECTED< 2.2SAFE ✓≥ 2.2
Updated Aug 21, 2026View on NVD →
Detail

FoodBakery is a popular WordPress theme used by restaurant owners to showcase their businesses online. It is a complete solution for food ordering and delivery systems that allows a restaurant owner to manage their menus, receive online payments, and even manage orders and deliveries from a single dashboard. The theme also includes different design templates, allowing owners to customize their sites to match their brand's unique look and feel.

Recently, a vulnerability was discovered in the WP FoodBakery WordPress plugin, which the FoodBakery theme uses. The vulnerability is identified as CVE-2021-24389. The issue arises from the plugin's inability to properly sanitize the foodbakery_radius parameter before it is outputted back into the response. This loophole leaves the site vulnerable to an unauthenticated Reflected Cross-Site Scripting (XSS) attack. 

The exploitation of this vulnerability allows an attacker to send a crafted link to a website visitor, which, when clicked, leads the victim to a compromised website. The attacker can use this link to execute malicious code by injecting scripts into the visitor's browser. Since the user trusts the site, they are more likely to fall victim to the attack, leading to the potential theft of sensitive information such as login credentials, credit card details, or even personal data. 

If you are concerned about the vulnerabilities of your digital assets, the s4e.io platform can help. By monitoring your websites 24/7, S4E helps you identify any potential vulnerabilities in your system, ensuring that your site remains secure and hacking attempts are thwarted. Upgrade now to access their pro features, and enjoy peace of mind knowing that your site is being actively monitored.

 

REFERENCES

Solution Advice

To protect against this vulnerability, site owners can take several precautions, including:

  • Updating the FoodBakery theme and WP FoodBakery plugin to the latest version.
  • Installing security plugins that are dedicated to resolving WordPress vulnerabilities.
  • Regularly scanning the site for vulnerabilities using automated tools.
  • Denying access to admin areas to untrusted users.
  • Using Content Security Policy (CSP) to prevent malicious scripts from loading on the site.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.