S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Feb 23, 2024

CVE-2021-24666 Scanner

CVE-2021-24666 scanner - SQL Injection (SQLi) vulnerability in Podlove Podcast Publisher plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.1k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-24666
9.8
CVSS

The Podlove Podcast Publisher WordPress plugin before 3.5.6 contains a 'Social & Donations' module (not activated by default), which adds the rest route '/services/contributor/(?P<id>[\d]+), takes an 'id' and 'category' parameters as arguments. Both parameters can be used for the SQLi.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Podlove Podcast Publisher
AFFECTED< 3.5.6SAFE ✓≥ 3.5.6
Updated Aug 21, 2026View on NVD →
Detail

Vulnerability Overview

CVE-2021-24666 allows unauthenticated attackers to perform SQL injections through vulnerable REST routes provided by the Social & Donations module in the Podlove Podcast Publisher plugin, potentially leading to sensitive data exposure or unauthorized database modifications.

Vulnerability Details

The vulnerability originates from the plugin's inability to properly sanitize the 'id' and 'category' parameters in the /services/contributor/(?P<id>[\d]+) REST route. An attacker can exploit this flaw to execute arbitrary SQL commands, leading to unauthorized access to the database or manipulation of its contents.

Possible Effects

If exploited, CVE-2021-24666 could result in:

  • Unauthorized access to sensitive information stored in the WordPress database.
  • Modification or deletion of critical data leading to website defacement or downtime.
  • Potential escalation of privileges allowing further exploitation of the WordPress site.

Why Choose S4E

S4E offers comprehensive vulnerability scanning solutions tailored to WordPress and its ecosystem. By subscribing to our services, users benefit from:

  • Real-time detection of emerging vulnerabilities like CVE-2021-24666.
  • Expert guidance on implementing effective security measures.
  • Access to a suite of tools designed to enhance website security posture. Join S4E today and safeguard your WordPress site against critical vulnerabilities and cyber threats.

References

Solution Advice
  • Immediate Update: Upgrade to Podlove Podcast Publisher version 3.5.6 or later, which contains the necessary patches.
  • Security Review: Audit the WordPress site for unauthorized changes or suspicious activities.
  • Restrict Access: Limit REST API access to trusted sources only.
  • Backup Regularly: Maintain up-to-date backups to quickly restore data in case of compromise.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-24666 scanner - SQL Injection (SQLi) vulnerability in Podlove Podcast Publisher plugin for WordPress | S4E