S4E just found a high top 10 tcp port service scan
medium·Product Based Web Vulnerabilities·Updated Feb 23, 2024

CVE-2021-24979 Scanner

CVE-2021-24979 scanner - Cross-Site Scripting (XSS) vulnerability in Paid Memberships Pro plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-24979
6.1
CVSS

The Paid Memberships Pro WordPress plugin before 2.6.6 does not escape the s parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Paid Memberships Pro
AFFECTED< 2.6.6SAFE ✓≥ 2.6.6
Updated Aug 21, 2026View on NVD →
Detail

Vulnerability Overview

The vulnerability stems from the plugin's failure to properly escape user inputs before incorporating them into the output within an admin page. This oversight allows for the execution of malicious scripts in the context of a logged-in user's session.

Vulnerability Details

Specifically, the issue occurs on the discount codes admin page of the Paid Memberships Pro plugin. The 's' parameter is not correctly sanitized before being echoed back, enabling attackers to inject malicious scripts that can be executed in the browser of any admin visiting the crafted URL.

Possible Effects

Exploitation of this vulnerability could lead to:

  • Theft of sensitive information from the admin's session.
  • Unauthorized actions being performed on the website as the admin.
  • Potential further attacks against the site or its users.

Why Choose S4E

S4E provides comprehensive vulnerability scanning and cybersecurity insights to protect your digital assets. By choosing us, you gain:

  • Access to advanced scanning tools for timely detection of vulnerabilities like CVE-2021-24979.
  • Expert recommendations for effective vulnerability management and remediation.
  • Continuous monitoring and alerts to keep your systems secure against emerging threats.

References

Solution Advice
  • Update Immediately: Ensure the Paid Memberships Pro plugin is updated to version 2.6.6 or later.
  • Validate User Input: Always validate and sanitize user inputs, especially those used in the output.
  • Use Security Plugins: Employ WordPress security plugins to detect and mitigate XSS vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.