S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-24554 Scanner

CVE-2021-24554 scanner - SQL Injection (SQLi) vulnerability in Paytm – Donation Plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.2k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-24554
7.2
CVSS

The Paytm – Donation Plugin WordPress plugin through 1.3.2 does not sanitise, validate or escape the id GET parameter before using it in a SQL statement when deleting donations, leading to an authenticated SQL injection issue

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Paytm – Donation Plugin
1.3.2
Updated Aug 21, 2026View on NVD →
Detail

The Paytm – Donation Plugin for WordPress is a plugin designed to facilitate donations through Paytm on a WordPress website. This plugin allows website owners to integrate Paytm donation options into their websites quickly and easily. By utilizing this tool, website owners can improve their ability to collect and manage donations from their audience without the need for extensive coding or development knowledge.

The CVE-2021-24554 vulnerability discovered in the Paytm – Donation Plugin for WordPress allows an authenticated SQL injection to occur. This vulnerability arises from the plugin's lack of sanitization, validation, or escape usage with the id GET parameter. This flaw makes it possible for an attacker to exploit the feature and gain unauthorized access to the website's database through SQL injection.

The exploitation of this vulnerability can lead to the stealing of sensitive data such as user login credentials, payment information, and confidential business data. It can also allow attackers to execute malicious code on the website, leading to the defacement of web pages, the installation of malware, or even complete website takeover.

Thanks to the pro features of the s4e.io platform, website owners can easily and quickly learn about vulnerabilities in their digital assets. The platform offers a comprehensive suite of features such as vulnerability scanning, incident response, and managed security services that help organizations stay one step ahead of cyber threats. By utilizing these powerful tools, website owners can ensure the security and reliability of their digital assets and eliminate the risk of vulnerabilities like CVE-2021-24554.

 

REFERENCES

Solution Advice

To protect against this vulnerability, website owners should install the latest version of the Paytm – Donation Plugin for WordPress, which addresses the CVE-2021-24554 vulnerability. Additionally, it is crucial to implement the following precautions:

  • Enabling automatic updates for WordPress plugins and core features.
  • Regularly updating installed plugins and themes to the latest version.
  • Enforcing strong password policies for all user accounts.
  • Implementing website firewalls and security plugins.
  • Regularly backing up website data and files.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.