S4E just found a high top 10 tcp port service scan
critical·Product Based Web Vulnerabilities·Updated Feb 23, 2024

CVE-2021-24731 Scanner

CVE-2021-24731 scanner - SQL Injection (SQLi) vulnerability in Pie Register plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.3k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-24731
9.8
CVSS

The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.7.1.6 does not properly escape user data before using it in a SQL statement in the wp-json/pie/v1/login REST API endpoint, leading to an SQL injection.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes
AFFECTED< 3.7.1.6SAFE ✓≥ 3.7.1.6
Updated Aug 21, 2026View on NVD →
Detail

Vulnerability Overview

CVE-2021-24731 represents a significant risk as it allows unauthenticated attackers to perform SQL injections via the affected REST API endpoint, potentially leading to unauthorized access, data leakage, or manipulation.

Vulnerability Details

The vulnerability stems from the plugin's handling of the user_login parameter in the wp-json/pie/v1/login endpoint. By exploiting this flaw, attackers can execute arbitrary SQL commands in the context of the website's database, which could compromise the site's integrity and data security.

Possible Effects

Exploitation of CVE-2021-24731 could result in:

  • Unauthorized access to sensitive database contents.
  • Manipulation or deletion of website data.
  • Disclosure of confidential information, potentially affecting both the site's operators and its users.

Why Choose S4E

S4E provides an all-encompassing approach to securing WordPress websites. By joining our platform, you gain:

  • Advanced scanning tools to detect vulnerabilities like CVE-2021-24731 in real-time.
  • Expert recommendations for vulnerability remediation and prevention.
  • Continuous monitoring to keep your site safeguarded against new and evolving threats. Opt for S4E and elevate your website's security posture today.

References

Solution Advice
  • Update Immediately: Ensure Pie Register is updated to version 3.7.1.6 or above.
  • Security Plugins: Utilize WordPress security plugins that offer SQL injection protection.
  • Access Controls: Review and restrict API access points, especially for unauthenticated users.
  • Regular Audits: Perform regular security audits of your WordPress installation and plugins.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-24731 scanner - SQL Injection (SQLi) vulnerability in Pie Register plugin for WordPress S4E