S4E just found a high top 10 tcp port service scan
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-34640 Scanner

CVE-2021-34640 scanner - Cross-Site Scripting (XSS) vulnerability in Securimage-WP-Fixed plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.1k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-34640
6.1
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.

The Securimage-WP-Fixed WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['PHP_SELF'] in the ~/securimage-wp.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 3.5.4.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
Securimage-WP-Fixedby Securimage-WP-Fixed
3.5.4
Updated Aug 21, 2026View on NVD →
Detail

Securimage-WP-Fixed is a popular WordPress plugin used for securing forms on a website. It protects against malicious form submissions by employing a standard CAPTCHA challenge-response mechanism. The idea behind this plugin is to prevent spam and bots from infiltrating forms and causing harm. Many website owners use this plugin to keep their forms secure and minimize the risk of attacks.

However, the Securimage-WP-Fixed has been found to have a critical vulnerability known as CVE-2021-34640. This flaw is caused by the use of "$_SERVER['PHP_SELF']" in the "~/securimage-wp.php" file, which allows attackers to insert arbitrary web scripts into the site. Cybercriminals can thereby take advantage of this vulnerability to execute dangerous attacks on the website, such as stealing sensitive data, launching phishing attacks, or infecting the site with malware.

When an attacker exploits the Securimage-WP-Fixed vulnerability, it can lead to devastating consequences for website owners. For instance, it can compromise the integrity of a website and lead to a loss of reputation. It can also result in a loss of revenue for businesses, as customer trust is eroded. Website owners could be exposed to legal troubles if visitor data is stolen. Additionally, website vulnerabilities can hurt a business's SEO ranking and lead to a reduction in traffic.

In conclusion, Securimage-WP-Fixed is a popular WordPress plugin that helps website owners protect their forms from spam and bots. However, the product is vulnerable to a critical flaw that can expose website owners to significant risks, such as theft of sensitive data, reputational damage, and financial loss. To secure against this vulnerability, organizations need to be proactive by continually updating their systems, monitoring possible vulnerabilities, and using the right security tools. With s4e.io, it's easy to stay up-to-date on security vulnerabilities and keep digital assets secure and under protection.

 

REFERENCES

Solution Advice

To safeguard against this vulnerability, the following precautions can be taken:

  • Ensure that the latest version of the Securimage-WP-Fixed plugin is installed regularly and all updates are checked and applied without delay.
  • Stop using the insecure "$_SERVER['PHP_SELF']" function, which could be dangerous in certain circumstances.
  • Use an updated version of WordPress as older versions could be more prone to this vulnerability.
  • Utilize a website security platform like securityforeveryone.com that could regularly assess and screen for potential security issues in the digital assets.
  • Maintain a good cybersecurity culture with efficient backup protocols.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-34640 scanner - Cross-Site Scripting (XSS) vulnerability in Securimage-WP-Fixed plugin for WordPress S4E