S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-34643 Scanner

CVE-2021-34643 scanner - Cross-Site Scripting (XSS) vulnerability in Skaut bazar plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.7k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-34643
6.1
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.

The Skaut bazar WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['PHP_SELF'] in the ~/skaut-bazar.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.3.2.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
Skaut Bazarby Skaut Bazar
1.3.2
Updated Aug 21, 2026View on NVD →
Detail

Skaut bazar is a WordPress plugin developed to enable users to create a classified website where individuals can sell, buy, or exchange goods and services. This plugin comes equipped with multiple features such as creating multiple categories and subcategories, searching for items by category or keyword, and browsing items through easy-to-use filter options. It was designed to simplify the process of setting up a classified website thereby making it accessible to everyone.

In a recent development though, a vulnerability, CVE-2021-34643 has been discovered in the Skaut bazar WordPress plugin. This vulnerability was detected due to the use of $_SERVER['PHP_SELF'] which allowed attackers to inject arbitrary web scripts. In essence, the vulnerability provided attackers with access to the system's data which could be used to steal sensitive information such as login credentials, personal information, or financial data.

When this vulnerability is exploited, it can lead to a domino effect of issues. The most significant being, sensitive data being compromised, translating into reputational damage to the user’s business or personal brand. Additionally, it could lead to an influx of unauthorized access to the user’s website, which can result in the exploitation of other vulnerabilities.

It is essential to keep abreast of all the latest vulnerabilities present in your systems. With S4E pro features, security becomes personal and replaces guesswork, assumptions, and reports with an active monitoring system that provides the latest data on new and emerging vulnerabilities. This platform provides, in real-time, insights on emerging vulnerabilities, and advice on how to close those gaps found within the digital assets. With pro features, anyone can easily and quickly learn about vulnerabilities in their digital assets.

 

REFERENCES

Solution Advice

To guard against these issues, it is essential to implement a few adjustments, such as:

  • Keep all plugins up to date to ensure that there are no security vulnerabilities
  • Utilize a website Application Firewall (WAF) that can look beyond typical firewall capabilities
  • Use strong passwords and multi-factor authentication,
  • Disable unused plugins and limit the grants to WordPress core files
  • Shift sensitive data, run backups, and test the backups

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-34643 scanner - Cross-Site Scripting (XSS) vulnerability in Skaut bazar plugin for WordPress | S4E