S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-24364 Scanner

CVE-2021-24364 scanner - Cross-Site Scripting (XSS) vulnerability in Jannah

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.5k
Times Used
continuous scan runs
3.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-24364
6.1
CVSS

The Jannah WordPress theme before 5.4.4 did not properly sanitize the options JSON parameter in its tie_get_user_weather AJAX action before outputting it back in the page, leading to a Reflected Cross-Site Scripting (XSS) vulnerability.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Jannahby TieLabs
AFFECTED< 5.4.4SAFE ✓≥ 5.4.4
Updated Aug 21, 2026View on NVD →
Detail

Jannah is a popular WordPress theme used by website owners to create professional and aesthetically pleasing websites. Users can customize the theme with a variety of features, including custom widgets, post layouts, and typography options, to meet their specific needs. The Jannah theme provides a responsive design that adapts to all screen sizes, ensuring a flawless browsing experience for all users. It is commonly used for news, magazine, and blog websites, among others.

Recently, a vulnerability was detected in the Jannah WordPress theme, marked as CVE-2021-24364. The issue stems from the theme's failure to properly sanitize the options JSON parameter before displaying it on the page, resulting in a Reflected Cross-Site Scripting (XSS) vulnerability. This means that an attacker could input malicious code into the page, which could then be executed when the victim accesses the affected site.

If this vulnerability is exploited, it could potentially lead to the theft of sensitive information, such as login credentials or credit card details, from unsuspecting victims. The attacker could also manipulate the content of the affected website, causing it to display false information or links to more harmful sites.

By using the pro features of the s4e.io platform, website owners can easily and quickly learn about vulnerabilities in their digital assets. The platform provides a comprehensive scan of all web-based assets and identifies potential security risks, including vulnerabilities in WordPress themes like Jannah. Users are then provided with actionable insights and recommendations on how to mitigate these risks and improve their website's overall security. By taking proactive steps to secure their website, website owners can protect themselves and their users from potential cyber threats.

 

REFERENCES

Solution Advice

To protect against this vulnerability, website owners should take the following precautions:

  • Update to the latest version of the Jannah theme, which includes a fix for this issue.
  • Use a web application firewall to identify and block malicious traffic.
  • Implement a content security policy (CSP) to prevent the execution of unauthorized scripts on the website.
  • Train employees and website administrators on how to properly handle sensitive information and avoid phishing attacks.
  • Conduct regular penetration testing to identify and address any vulnerabilities in the website's security posture.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.