S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-38314 Scanner

CVE-2021-38314 scanner - Information Disclosure vulnerability in Gutenberg Template Library & Redux Framework plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.4k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
20
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-38314
5.3
CVSSmedium
Exploitable remotely over the internet · no authentication required.

The Gutenberg Template Library & Redux Framework plugin <= 4.2.11 for WordPress registered several AJAX actions available to unauthenticated users in the `includes` function in `redux-core/class-redux-core.php` that were unique to a given site but deterministic and predictable given that they were based on an md5 hash of the site URL with a known salt value of '-redux' and an md5 hash of the previous hash with a known salt value of '-support'. These AJAX actions could be used to retrieve a list of active plugins and their versions, the site's PHP version, and an unsalted md5 hash of site’s `AUTH_KEY` concatenated with the `SECURE_AUTH_KEY`.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Gutenberg Template Library & Redux Frameworkby Redux.io
4.2.11
Updated Aug 19, 2026View on NVD →
Detail

The Gutenberg Template Library & Redux Framework plugin for WordPress is a popular tool that enables users to develop custom WordPress themes and plugins quickly. It provides an extensive range of pre-built blocks and templates, making it simpler for developers to construct their designs. The plugin offers a simple, drag-and-drop interface that allows users to create complex layouts without coding knowledge. 

Recently, a critical vulnerability was detected in this plugin that allows unauthorized access to sensitive data. The CVE-2021-38314 vulnerability occurs when an attacker exploits a specific AJAX function that is available to unauthenticated users. The attackers can use the AJAX actions to obtain a list of active plugins and their versions, the site's PHP version, and unsalted md5 hash of site’s `AUTH_KEY` concatenated with the `SECURE_AUTH_KEY.` 

This vulnerability can lead to severe consequences when exploited, allowing hackers to gain access to the site's sensitive information. With this data, they can launch further attacks, exploit the WordPress core, and create privileged arbitrary files remotely. They can alter the site's content, add malware, and execute other malicious actions on the compromised system.

In conclusion, by subscribing to S4E, individuals can mitigate their digital assets and protect themselves from the latest vulnerabilities. As S4E continuously updates and scans their client's digital assets, users will have access to real-time protection against the latest vulnerabilities and cyber threats. Don't wait until it's too late, subscribe to S4E now for robust protection.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users should take the following precautions:

  • Update to the latest version of the Gutenberg Template Library & Redux Framework plugin as soon as possible.
  • Limit administrative access to the site to a trusted network.
  • Block or limit unauthorized access to the site's AJAX functions using a firewall or other security tool.
  • Regularly monitor the site's logs and configurations for any unusual activities or changes.
  • Use a reputable security tool to perform an automated security scan and vulnerability assessment.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.