S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-24997 Scanner

CVE-2021-24997 scanner - Information Disclosure vulnerability in WP Guppy plugin for Wordpress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.5k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-24997
6.5
CVSS

The WP Guppy WordPress plugin before 1.3 does not have any authorisation in some of the REST API endpoints, allowing any user to call them and could lead to sensitive information disclosure, such as usernames and chats between users, as well as be able to send messages as an arbitrary user

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
WP Guppy
AFFECTED< 1.3SAFE ✓≥ 1.3
Updated Aug 21, 2026View on NVD →
Detail

The WP Guppy plugin for WordPress is a tool designed for the purpose of helping website owners and administrators to provide a chat service between users. It is a simple and cost-effective solution that allows site visitors to connect with one another in real-time. With WP Guppy, website owners can add a chat feature to their site with ease. Users can chat privately or in groups, providing a sense of community among site visitors.

However, despite the benefits of the WP Guppy plugin, it has been found to contain a serious vulnerability, CVE-2021-24997. This vulnerability is a result of a lack of authentication in some of the plugin's REST API endpoints. As a result, anyone can call these endpoints, which can potentially lead to sensitive information disclosure. This vulnerability could expose users' personal data like usernames and chats between users. Even worse, it allows attackers to send messages as an arbitrary user.

When this vulnerability is exploited, it can lead to significant consequences for both website owners and users. Attackers could gain access to user data such as emails, phone numbers, and even passwords. They could use this information for identity theft or extortion. The risk is particularly high for sites that handle sensitive data like banking or healthcare information.

In conclusion, the WP Guppy plugin is a valuable tool for website owners to provide a chat service between users. However, it is critical to ensure the latest version of the plugin is used and that proper security precautions are taken to protect against vulnerabilities like CVE-2021-24997. By staying informed about vulnerabilities and taking proactive measures, website owners can safeguard their digital assets. Thanks to the pro features of s4e.io, it's easy and quick to learn about vulnerabilities in your digital assets and how to protect against them.

 

REFERENCES

Solution Advice

To protect against this vulnerability, there are a few precautions that website owners and administrators can take:

  • Upgrade to the latest version of the WP Guppy plugin (1.3 or later), which includes fixes for this vulnerability.
  • Limit access to the plugin's REST API endpoints to authorized users only.
  • Use a reliable security solution to monitor your website for suspicious activity.
  • Regularly review and update your website's security policies and procedures.
  • Consider using a web application firewall (WAF) to protect your website against attacks.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-24997 scanner - Information Disclosure vulnerability in WP Guppy plugin for Wordpress | S4E