S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-24947 Scanner

CVE-2021-24947 scanner - Cross-Site Request Forgery (CSRF) vulnerability in RVM - Responsive Vector Maps plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.4k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-24947
6.5
CVSS

The RVM WordPress plugin before 6.4.2 does not have proper authorisation, CSRF checks and validation of the rvm_upload_regions_file_path parameter in the rvm_import_regions AJAX action, allowing any authenticated user, such as subscriber, to read arbitrary files on the web server

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
RVM – Responsive Vector Maps
AFFECTED< 6.4.2SAFE ✓≥ 6.4.2
Updated Aug 21, 2026View on NVD →
Detail

RVM - Responsive Vector Maps is a popular WordPress plugin used to create interactive maps and display data on websites. This plugin provides users with a wide range of customizable maps that can be embedded on their websites. RVM has been widely used by businesses, bloggers, and web developers to enhance their website design and provide engaging content to their audience. The plugin has gained much popularity for its flexibility and ease of use.

Recently, a vulnerability was detected in the RVM WordPress plugin, CVE-2021-24947. This vulnerability stems from a lack of proper authorisation, CSRF checks, and validation of the 'rvm_upload_regions_file_path' parameter in the 'rvm_import_regions' AJAX action. This exploit can allow any authenticated user, even subscribers, to access arbitrary files on the web server. It can lead to severe repercussions for the website owner, including unauthorised access, data leaks, and system compromise. 

The CVE-2021-24947 vulnerability can have significant consequences when exploited. This exploit can allow attackers to obtain sensitive information or even gain unauthorised access to the web server. Attackers can use the vulnerability to infiltrate a site, install malware, delete or modify files, or steal sensitive data. This can lead to lost revenue, data breaches, and loss of customer trust. 

In conclusion, being aware of and addressing vulnerabilities in digital assets, such as WordPress plugins, is crucial to maintaining website security. The s4e.io platform offers pro features that allow users to easily and quickly identify and mitigate vulnerabilities in their digital assets, such as RVM - Responsive Vector Maps. In this way, users can ensure the safety of their websites and protect against unauthorized access and data breaches. Remember, taking security precautions is always better than dealing with the aftermath of exploitation.

 

REFERENCES

Solution Advice

To protect against this vulnerability, several precautions can be taken, including:

  • Updating plugins and themes regularly to their latest versions.
  • Implementing a web application firewall (WAF) to filter traffic and block potential attacks.
  • Limiting admin privileges and employing strong passwords.
  • Disabling file editing through the WordPress admin panel.
  • Regularly backing up WordPress databases and files.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-24947 scanner - Cross-Site Request Forgery (CSRF) vulnerability in RVM - Responsive Vector Maps plugin for WordPress | S4E