S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Feb 23, 2024

CVE-2021-24627 Scanner

CVE-2021-24627 scanner - SQL Injection (SQLi) vulnerability in G Auto-Hyperlink plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.1k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-24627
7.2
CVSS

The G Auto-Hyperlink WordPress plugin through 1.0.1 does not sanitise or escape an 'id' GET parameter before using it in a SQL statement, to select data to be displayed in the admin dashboard, leading to an authenticated SQL injection

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
G Auto-Hyperlink
1.0.1
Updated Aug 21, 2026View on NVD →
Detail

Vulnerability Overview

The vulnerability arises from the plugin's failure to sanitize the 'id' GET parameter before incorporating it into a SQL query. This flaw allows authenticated users to manipulate SQL queries, leading to unauthorized database access.

Vulnerability Details

By exploiting this SQL injection vulnerability, an attacker, authenticated as a low-privileged user, can perform database queries that retrieve, modify, or delete data. The attacker can manipulate the 'id' parameter in the plugin's admin dashboard URL to inject malicious SQL commands.

Possible Effects

Exploitation of this vulnerability could lead to:

  • Unauthorized access to sensitive data stored in the WordPress database.
  • Modification or deletion of data, which could compromise the website's integrity and availability.
  • Escalation of privileges by manipulating the database to grant higher-level access to the attacker.

Why Choose S4E

S4E provides a robust platform for identifying and mitigating vulnerabilities like CVE-2021-24627. By becoming a member, you gain access to:

  • A wide array of vulnerability scanners tailored to detect specific threats.
  • Expert advice on vulnerability remediation and security best practices.
  • Continuous monitoring services to alert you of new vulnerabilities and threats as they emerge. Investing in S4E equips you with the tools to maintain a secure and resilient online presence against evolving cybersecurity challenges.

References

Solution Advice
  • Immediate Update: Upgrade to the latest version of the G Auto-Hyperlink plugin that has patched this vulnerability.
  • Restrict Access: Limit dashboard access to trusted users only.
  • Use Security Plugins: Implement WordPress security plugins that offer firewall and database security features.
  • Regularly Monitor: Keep an eye on user activities and access logs for any suspicious actions.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-24627 scanner - SQL Injection (SQLi) vulnerability in G Auto-Hyperlink plugin for WordPress | S4E