S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-24387 Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in WP Pro Real Estate 7 theme for WordPress affects v. before 3.1.1.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.7k
Times Used
continuous scan runs
3.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-24387
6.1
CVSS

The WP Pro Real Estate 7 WordPress theme before 3.1.1 did not properly sanitise the ct_community parameter in its search listing page before outputting it back in it, leading to a reflected Cross-Site Scripting which can be triggered in both unauthenticated or authenticated user context

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
WP Pro Real Estate 7by Contempoinc
AFFECTED< 3.1.1SAFE ✓≥ 3.1.1
Updated Aug 21, 2026View on NVD →
Detail

The WP Pro Real Estate 7 WordPress theme is a popular tool used by real estate agents, brokers, and property managers to showcase, market and sell properties online. This responsive theme is packed with a myriad of features and widgets such as advanced search capabilities, detailed property listings, Google Maps integration, and IDX/MLS compatibility. Its customizable design and layouts make it easy for users to create a professional-looking website that caters to their unique business needs and objectives.

However, despite its many features, the WP Pro Real Estate 7 WordPress theme has been found to be vulnerable to a Cross-Site Scripting  (XSS) vulnerability. The CVE-2021-24387 vulnerability was identified in its search listing page where the theme did not properly sanitize the 'ct_community' parameter before outputting it back in the page, allowing attackers to inject malicious script code in the user's browser. This vulnerability can be exploited by both authenticated and unauthenticated attackers, leading to the theft of sensitive information such as login credentials, personal data and financial information.

Exploiting this vulnerability can have dire consequences for businesses and individuals alike. In addition to exposing the users of the website to potential theft of their personal and financial data, attackers can further use this vulnerability to plant other harmful malware on the website or hijack the website completely. As a result, it is imperative for website owners and administrators to take immediate action to prevent malicious attacks.

At s4e.io, we believe that every website owner should have access to the best tools and resources to keep their digital assets secure. With our platform's pro features, users can easily and quickly learn about vulnerabilities in their digital assets and get practical advice on how to protect themselves from attacks. We are committed to helping our clients stay ahead of the curve by providing them with the latest information and insights on emerging cyber threats. Contact us today to learn how we can help you secure your website and protect your business.

 

REFERENCES

Solution Advice

Fortunately, precautions can be taken to protect against this vulnerability, including but not limited to:

  • Updating the WP Pro Real Estate 7 WordPress theme to its latest version (3.1.1), which includes a patch for the XSS vulnerability.
  • Ensuring that all website themes and plugins are kept updated and patched to minimise the risk of emerging vulnerabilities.
  • Employing a web application firewall (WAF) that can detect and prevent XSS attacks from reaching the website.
  • Using Content Security Policy (CSP) to help mitigate the risk of XSS attacks on the website.
  • Conducting regular scans and vulnerability assessments to detect and address vulnerabilities and avoid future exploitation.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.