S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-24347 Scanner

CVE-2021-24347 scanner - Unrestricted File Upload vulnerability in SP Project & Document Manager plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.7k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-24347
8.8
CVSS

The SP Project & Document Manager WordPress plugin before 4.22 allows users to upload files, however, the plugin attempts to prevent php and other similar files that could be executed on the server from being uploaded by checking the file extension. It was discovered that php files could still be uploaded by changing the file extension's case, for example, from "php" to "pHP".

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
SP Project & Document Manager
AFFECTED< 4.22SAFE ✓≥ 4.22
Updated Aug 21, 2026View on NVD →
Detail

The SP Project & Document Manager plugin for WordPress is a tool that allows users to upload files to their website. It's specifically designed to manage documents and projects, creating an efficient workflow for project teams and businesses. The plugin offers various features, such as organizing files according to categories, tagging files, adding notes, and setting permissions. It can be installed on any WordPress site and is easily customizable to suit specific needs.

CVE-2021-24347 is a vulnerability that has been discovered in the SP Project & Document Manager plugin. It is caused by a flaw in the plugin's code that allows users to upload PHP files that can be executed on the server. The vulnerability arises from the plugin's attempts to restrict certain file extensions, and attackers can easily exploit it by changing file extensions' case. As a result, hackers can gain access to the server and potentially steal sensitive information.

This vulnerability can lead to severe consequences for website owners, especially those who run online businesses. Attackers can easily gain access to the website and manipulate the site's content, leading to defacement, data theft, or the installation of malware. Besides, website visitors can also be at risk of cyberattacks if hackers use the site for distributing malicious software. It's crucial to address and resolve the vulnerability as soon as possible to avoid any potential risks.

s4e.io provides a comprehensive platform to help website owners assess their website's security posture accurately. Its pro features allow users to identify and remediate vulnerabilities rapidly, thereby minimizing the risk of cyberattacks. The platform's easy-to-use and intuitive interface helps users navigate through the security measures and remediation process, even without extensive technical knowledge. By subscribing to s4e.io, website owners can safeguard their digital assets and protect themselves and their customers from potential security breaches.

 

REFERENCES

Solution Advice

To protect against the CVE-2021-24347 vulnerability, website owners can take the following measures:

  • Update the SP Project & Document Manager plugin to the latest version.
  • Ensure that all other plugins and themes installed on the website are also up to date.
  • Implement a web application firewall (WAF) to filter out suspicious network traffic.
  • Enable server-side security measures, such as Secure Sockets Layer (SSL) certificates and intrusion detection and prevention systems (IDPS).
  • Conduct regular security audits and scans to identify any vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-24347 scanner - Unrestricted File Upload vulnerability in SP Project & Document Manager plugin for WordPress | S4E