S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-24987 Scanner

CVE-2021-24987 scanner - Cross-Site Scripting (XSS) vulnerability in Social Share, Social Login and Social Comments Plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.4k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-24987
6.1
CVSS

The Social Share, Social Login and Social Comments Plugin WordPress plugin before 7.13.30 does not sanitise and escape the urls parameter in its the_champ_sharing_count AJAX action (available to both unauthenticated and authenticated users) before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Social Share, Social Login and Social Comments Plugin – Super Socializer
AFFECTED< 7.13.30SAFE ✓≥ 7.13.30
Updated Aug 21, 2026View on NVD →
Detail

The Social Share, Social Login and Social Comments Plugin for WordPress is a powerful tool that helps website owners to enhance their social media presence. This plugin enables users to share, login, and comment via social media platforms such as Facebook, Twitter, and LinkedIn. It is extensively used by bloggers, digital marketers, and website owners to increase their reach and audience engagement. The plugin has been widely popular for its simple user interface which is easy for anyone to use.

One of the major issues detected in the Social Share, Social Login and Social Comments Plugin for WordPress is the CVE-2021-24987 vulnerability. The vulnerability has been identified in the plugin before version 7.13.30. This vulnerability occurs as the plugin does not properly sanitise and escape the urls parameter in its the_champ_sharing_count AJAX action, which is available to both authenticated and unauthenticated users. This loophole could be exploited by attackers, who could inject malicious code in the responses and execute it in the webpage.

If this vulnerability is exploited, it could lead to severe consequences. An attacker could gain remote access to the website, spread malware, phishing attacks or even steal sensitive data such as user credentials, personal and financial information, etc. This could result in damage to both the website owner's reputation and their finances. In the worst-case scenario, it could lead to complete website shutdown, resulting in loss of business opportunities and revenue.

The Social Share, Social Login and Social Comments Plugin WordPress plugin before 7.13.30 does not sanitise and escape the urls parameter in its the_champ_sharing_count AJAX action (available to both unauthenticated and authenticated users) before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue.

In conclusion, the Social Share, Social Login and Social Comments Plugin for WordPress is an invaluable tool for any website owner looking to enhance their social media following. However, this plugin is also vulnerable to attacks that could lead to severe consequences. To protect your website, it is essential to stay updated with the latest plugins, conduct regular website scans, backup data, and monitor website activity. Fortunately, with the pro features of s4e.io, users can quickly identify any vulnerabilities in their digital assets and take appropriate action.

 

REFERENCES

Solution Advice

To protect against this vulnerability, precautions can be taken as follows:

  • Update your Social Share, Social Login and Social Comments Plugin for WordPress to version 7.13.30 or above as it has already been patched.
  • Regularly monitor your website activity and third-party plugins.
  • Run a regular scan of your website using a reputable security tool.
  • Review your website's content and user data thoroughly to prevent any vulnerabilities.
  • Backup your website data regularly to safeguard against any loss of data in the event of an attack.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.