S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-24472 Scanner

CVE-2021-24472 scanner - Server-Side-Request-Forgery (SSRF) vulnerability in QT KenthaRadio theme and OnAir2 plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-24472
9.8
CVSS

The OnAir2 WordPress theme before 3.9.9.2 and QT KenthaRadio WordPress plugin before 2.0.2 have exposed proxy functionality to unauthenticated users, sending requests to this proxy functionality will have the web server fetch and display the content from any URI, this would allow for SSRF (Server Side Request Forgery) and RFI (Remote File Inclusion) vulnerabilities on the website.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
QT KenthaRadioby QantumThemes
AFFECTED< 2.0.2SAFE ✓≥ 2.0.2
OnAir2by QantumThemes
AFFECTED< 3.9.9.2SAFE ✓≥ 3.9.9.2
Updated Aug 21, 2026View on NVD →
Detail

The OnAir2 WordPress theme is a popular tool used for creating professional, radio station websites while the QT KenthaRadio WordPress plugin is widely used to enhance the functionality of radio themes. These products allow developers to easily build scalable and attractive websites that enable seamless streaming and playback of music, podcasts, and live shows.

However, as recently discovered, the QT KenthaRadio WordPress plugin and OnAir2 WordPress theme prior to version 3.9.9.2 have a serious vulnerability, also known as CVE-2021-24472. This vulnerability is present because the products have exposed proxy functionality that allows unauthenticated users to make requests in the webserver, ultimately giving access to any URI. This exposes these products to the dangers of Server Side Request Forgery (SSRF) and Remote File Inclusion (RFI) attacks, which can compromise website security and cause severe damage.

In the case of a successful exploitation of this vulnerability, cybercriminals can potentially manipulate the website's functionality and gain access to sensitive information. By exploiting the vulnerability, attackers can trick the user into "visiting" websites on their behalf, leading to injecting Trojan files and phishing codes into the website, which could cause the website to become unresponsive, crash, and even possibly lose crucial data.

In conclusion, with the support of the s4e.io platform's advanced security tools, it is now easier to detect and remedy vulnerabilities in digital assets. The vulnerabilities in OnAir2 and QT KenthaRadio serve as a reminder of how crucial it is to keep software updated to ensure optimal website security. By following the necessary precautions and adopting the latest security tools, website owners can keep their assets protected from any potential breaches and further risks.

 

REFERENCES

Solution Advice

To protect against this vulnerability, we recommend the following precautions:

  • Update the OnAir2 WordPress theme and QT KenthaRadio WordPress plugin to the latest version. 
  • Firewall configuration changes to block malicious requests sent to the proxy functionality. 
  • Configure multiple firewalls to monitor and filter network traffic.
  • Security scans and regular penetration testing to keep pace with new security threats.
  • Restrict access to sensitive areas of the website and database to prevent unauthorized access and mitigate potential damage.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-24472 scanner - Server-Side-Request-Forgery (SSRF) vulnerability in QT KenthaRadio theme and OnAir2 plugin for WordPress | S4E