S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Feb 23, 2024

CVE-2021-24791 Scanner

CVE-2021-24791 scanner - SQL Injection (SQLi) vulnerability in Header Footer Code Manager plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.1k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-24791
7.2
CVSS

The Header Footer Code Manager WordPress plugin before 1.1.14 does not validate and escape the "orderby" and "order" request parameters before using them in a SQL statement when viewing the Snippets admin dashboard, leading to SQL injections

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Header Footer Code Manager
AFFECTED< 1.1.14SAFE ✓≥ 1.1.14
Updated Aug 21, 2026View on NVD →
Detail

Vulnerability Overview

CVE-2021-24791 allows authenticated attackers (with admin privileges) to execute SQL injections in the Header Footer Code Manager plugin, potentially leading to data exposure or unauthorized database modifications.

Vulnerability Details

The flaw is found in the handling of the "orderby" and "order" request parameters in the plugin's Snippets admin dashboard. By manipulating these parameters, an attacker can inject and execute arbitrary SQL commands, leading to unauthorized data access or manipulation.

Possible Effects

Exploitation of CVE-2021-24791 can lead to:

  • Unauthorized access to sensitive WordPress database information.
  • Modification or deletion of database content, potentially causing website malfunction or data loss.
  • Escalation of privileges within the WordPress environment.

Why Choose S4E

S4E offers robust security solutions to protect WordPress websites from vulnerabilities like CVE-2021-24791. Our platform provides:

  • Advanced scanning tools to detect vulnerabilities swiftly.
  • Expert advice on mitigation and preventive measures.
  • Regular updates and insights on emerging security threats. Opt for S4E to fortify your WordPress site against sophisticated cyber threats.

References

Solution Advice
  • Update Immediately: Upgrade to Header Footer Code Manager version 1.1.14 or newer.
  • Admin Account Review: Ensure that only trusted users have administrative access.
  • Database Backup: Regularly back up the database to recover from potential data manipulation.
  • Monitor Logs: Check for unusual database queries or changes that may indicate exploitation attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-24791 scanner - SQL Injection (SQLi) vulnerability in Header Footer Code Manager plugin for WordPress | S4E