S4E just found a high [ai] pa ssl inspection control
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-24407 Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in Jannah affects v. before 5.4.5.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
1
Times Used
by S4E users
1
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-24407
6.1
CVSS

The Jannah WordPress theme before 5.4.5 did not properly sanitize the 'query' POST parameter in its tie_ajax_search AJAX action, leading to a Reflected Cross-site Scripting (XSS) vulnerability.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Jannahby TieLabs
AFFECTED< 5.4.5SAFE ✓≥ 5.4.5
Updated Aug 19, 2026View on NVD →
Detail

Jannah is a WordPress theme that is designed for news and magazine websites. It is a highly customizable and user-friendly theme that allows webmasters to easily create news portals, online magazines, and blogs. With its modern and clean design, Jannah has become a popular choice for WordPress users who want to create engaging and visually appealing websites.

Recently, a vulnerability was detected in the Jannah WordPress theme software, known as CVE-2021-24407. The vulnerability was related to the way the 'query' POST parameter was sanitized in the tie_ajax_search AJAX action, which can lead to Reflected Cross-site Scripting (XSS) attacks.

When exploited, this vulnerability can allow an attacker to inject malicious scripts into the web pages viewed by the website's visitors. This can lead to a range of malicious activities such as stealing sensitive information, hijacking user sessions, and spreading malware.

At s4e.io, we provide detailed and up-to-date information about vulnerabilities in digital assets, including the Jannah WordPress theme. Our platform offers advanced features that help webmasters protect their websites from potential security threats. By subscribing to our platform, readers can easily and quickly learn about vulnerabilities in their digital assets, including the Jannah WordPress theme, and take appropriate measures to ensure their website's security.

 

REFERENCES

Solution Advice

To protect against this vulnerability, webmasters using Jannah WordPress theme can take the following precautions:

  • Update to the latest version of the Jannah WordPress theme.
  • Enable automatic updates to ensure that the theme is always up-to-date.
  • Monitor website traffic and look for any suspicious activities.
  • Use a reliable web firewall to block malicious requests.
  • Regularly backup website data and files to minimize the impact of any successful attacks.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.