S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-24342 Scanner

CVE-2021-24342 scanner - Cross-Site Scripting (XSS) vulnerability in JNews plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.1k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-24342
6.1
CVSS

The JNews WordPress theme before 8.0.6 did not sanitise the cat_id parameter in the POST request /?ajax-request=jnews (with action=jnews_build_mega_category_*), leading to a Reflected Cross-Site Scripting (XSS) issue.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
JNews
AFFECTED< 8.0.6SAFE ✓≥ 8.0.6
Updated Aug 21, 2026View on NVD →
Detail

JNews is a popular WordPress theme used by bloggers and online publishers to create engaging and visually appealing websites. With its user-friendly interface and wide range of customization options, JNews allows users to create unique and interactive content that speaks to their target audience. It comes with a variety of features and options, including pre-designed templates, custom widgets, and a powerful drag-and-drop page builder, making it easy for users to design their website with minimal coding. 

Recent security research has uncovered a critical vulnerability in the JNews plugin that could leave users' websites vulnerable to attack. CVE-2021-24342 is a Reflected Cross-Site Scripting (XSS) issue that occurs when the cat_id parameter in the POST request /?ajax-request=jnews (with action=jnews_build_mega_category_*) is not properly sanitized. This means that an attacker can inject malicious code into the cat_id parameter, which will be executed when a user visits a specific page on the website.

If exploited, this vulnerability can lead to serious consequences for website owners, including data theft, financial loss, and reputation damage. Hackers can use the XSS vulnerability to steal sensitive information, such as login credentials, credit card numbers, and personal data, from users who visit the affected page. They can also redirect users to fake websites or install malware on their devices, causing further harm.

In conclusion, the JNews plugin for WordPress is a popular tool for publishers and bloggers. However, the recently discovered CVE-2021-24342 vulnerability can cause serious harm to websites if left unaddressed. By taking the necessary precautions and staying informed about web security, users can protect their digital assets from potential attacks. For those who want a quick and easy way to learn more about vulnerabilities in their digital assets, s4e.io offers pro features that provide comprehensive security audits and real-time vulnerability detection.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users can take the following precautions:

  • Update to the latest version of JNews (8.0.6 or higher) which fixes the vulnerability.
  • Use a web application firewall (WAF) to monitor and block malicious traffic.
  • Regularly scan your website for vulnerabilities using a reliable vulnerability scanner.
  • Monitor your website logs for any suspicious activity and investigate any potential security breaches.
  • Educate yourself and your team on web security best practices to prevent future attacks.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.