S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-24210 Scanner

Detects 'Open Redirect' vulnerability in PhastPress plugin for WordPress affects v. before 1.111.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.3k
Times Used
continuous scan runs
4.2k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-24210
6.1
CVSS

There is an open redirect in the PhastPress WordPress plugin before 1.111 that allows an attacker to malform a request to a page with the plugin and then redirect the victim to a malicious page. There is also a support comment from another user one year ago (https://wordpress.org/support/topic/phast-php-used-for-remote-fetch/) that says that the php involved in the request only go to whitelisted pages but it's possible to redirect the victim to any domain.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
PhastPress
AFFECTED< 1.111SAFE ✓≥ 1.111
Updated Aug 21, 2026View on NVD →
Detail

PhastPress is a WordPress plugin that is designed to optimize the performance of websites. It is a product that is used for improving the loading time of websites so that the online visitors can have a much better experience. PhastPress provides a range of optimization services, including advanced caching, resource minification, and image optimization. It is a plugin that is widely used by website owners who want to improve the user experience and boost their SEO ranking.

The CVE-2021-24210 vulnerability is a serious security flaw that affects the PhastPress WordPress plugin. This vulnerability allows attackers to redirect users to malicious websites by exploiting an open redirect flaw. The flaw enables attackers to manipulate the request to a page with the plugin and redirect the victim to a malicious page. The flaw was discovered in the version of the plugin that was released before 1.111.

This vulnerability can lead to a range of negative consequences when exploited. The attacker can redirect users to phishing websites or websites that have malware, which can harm the user's computer. It can also cause reputational damage to businesses as the attack can be linked to their website. Moreover, if a website is infected, it can get blacklisted by search engines, which will hurt the SEO - making it harder for businesses to reach online audiences.

In conclusion, security vulnerabilities can be a serious concern for any website. However, with the pro features of the s4e.io platform, you can easily and quickly learn about vulnerabilities and best practices to secure your website. The platform provides operators with detailed reports on the status of their digital assets and ensures that your website is safeguarded against attacks, thereby preventing vulnerabilities like CVE-2021-24210. Be proactive and take the necessary steps to secure your website today!

 

REFERENCES

Solution Advice

To protect against this vulnerability, it is essential to follow certain precautions. Here are some best practices to safeguard against the CVE-2021-24210 vulnerability:

  • Update PhastPress to the latest version.
  • Keep WordPress up-to-date.
  • Be cautious when clicking on links that look suspicious.
  • Use a web application firewall to detect and block attacks.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.