S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-25067 Scanner

CVE-2021-25067 scanner - Cross-Site Scripting (XSS) vulnerability in Landing Page Builder plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-25067
5.4
CVSS

The Landing Page Builder WordPress plugin before 1.4.9.6 was affected by a reflected XSS in page-builder-add on the ulpb_post admin page.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Landing Page Builder – Lead Page – Optin Page – Squeeze Page – WordPress Landing Pages
AFFECTED< 1.4.9.6SAFE ✓≥ 1.4.9.6
Updated Aug 21, 2026View on NVD →
Detail

The Landing Page Builder plugin for WordPress is a software tool that is used to create visually stunning landing pages for websites. With the help of this plugin, users can easily create and customize landing pages to attract visitors, promote products or services, and generate leads. The plugin has a user-friendly interface and a variety of templates and design elements that make the landing page creation process easy and efficient.

The CVE-2021-25067 vulnerability detected in the Landing Page Builder plugin is a reflected XSS that affects the page-builder-add on the ulpb_post admin page. This vulnerability allows an attacker to inject and execute malicious code into the victim's web browser by manipulating user input. It can be triggered when a user clicks on a specially crafted link or visits a page containing the malicious code.

When exploited, this vulnerability can lead to several negative consequences for website owners and their visitors. An attacker can steal sensitive information like usernames, passwords, and credit card details, install malware on the victim's system, or hijack the victim's web sessions. This can result in financial loss, reputation damage, and legal liabilities for the affected parties.

In conclusion, pro features of the s4e.io platform can help website owners and IT professionals to stay informed about vulnerabilities in their digital assets easily and quickly. By using these features, users can receive alerts about new vulnerabilities, assess their impact on their assets, and take appropriate actions to protect themselves against cyber threats. It is essential to stay vigilant and proactive in securing your digital assets to prevent cyber attacks and maintain business continuity.

 

REFERENCES

Solution Advice

To protect against this vulnerability, website owners can take the following precautions:

  • Update the Landing Page Builder plugin to the latest version that fixes the vulnerability.
  • Use a web application firewall (WAF) to detect and block XSS attacks.
  • Disable or limit user input on pages that are vulnerable to XSS attacks.
  • Sanitize and validate user input to prevent injection of malicious code.
  • Educate users about the risks of clicking on suspicious links or visiting untrusted websites.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-25067 scanner - Cross-Site Scripting (XSS) vulnerability in Landing Page Builder plugin for WordPress | S4E