S4E just found an informational wpcode – insert headers and footers + custom code snippets – wordpress code manager detection scanner
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-24287 Scanner

CVE-2021-24287 scanner - Cross-Site Scripting (XSS) vulnerability in Select All Categories and Taxonomies plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.4k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-24287
6.1
CVSS

The settings page of the Select All Categories and Taxonomies, Change Checkbox to Radio Buttons WordPress plugin before 1.3.2 did not properly sanitise the tab parameter before outputting it back, leading to a reflected Cross-Site Scripting issue

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Select All Categories and Taxonomies, Change Checkbox to Radio Buttonsby Moove Agency
AFFECTED< 1.3.2SAFE ✓≥ 1.3.2
Updated Aug 21, 2026View on NVD →
Detail

The Select All Categories and Taxonomies plugin for WordPress is a tool that allows users to easily select and organize categories and taxonomies on their website. This plugin simplifies the process of managing content and improving website navigation. The plugin is popular among WordPress users who are looking for an efficient way to manage their website's taxonomy.

The CVE-2021-24287 vulnerability was recently detected in the Select All Categories and Taxonomies plugin before 1.3.2. This vulnerability was caused by the plugin's failure to properly sanitize the tab parameter before outputting it back, resulting in a reflected Cross-Site Scripting issue. This issue may allow attackers to inject malicious code into a website's tags and categories, potentially compromising the security of the entire site.

When exploited, this vulnerability can lead to serious consequences for website owners. Attackers who successfully inject malicious code can gain unauthorized access to sensitive information and undermine website security. They may also use the compromised website to launch further attacks on other sites and systems. It is crucial to address this vulnerability as soon as possible to prevent any damage to your website or digital assets.

In conclusion, vulnerabilities like CVE-2021-24287 highlight the importance of maintaining website security. By taking the necessary precautions and regularly scanning for vulnerabilities, website owners can protect against potential attack and safeguard their digital assets. With the pro features of the s4e.io platform, readers of this article can easily and quickly learn about the vulnerabilities in their digital assets and take proactive steps to ensure their website remains safe and secure.

 

REFERENCES

Solution Advice

To mitigate this threat, users of the Select All Categories and Taxonomies plugin before version 1.3.2 must update their software immediately. Moreover, users should consider additional security measures to protect their systems against such threats. Here are some precautionary measures:

  • Always keep up-to-date with the latest security patches and software updates.
  • Use strong passwords and implement multi-factor authentication.
  • Disable unused plugins, themes, and services.
  • Use a reputable web application firewall (WAF) to protect against SQL injection and Cross-Site Scripting attacks.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.