S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-25052 Scanner

CVE-2021-25052 scanner - Cross-Site Request Forgery (CSRF) vulnerability in Button Generator plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-25052
8.8
CVSS

The Button Generator WordPress plugin before 2.3.3 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as with data:// or http:// protocols), thus leading to CSRF RCE.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Button Generator – easily Button Builder
AFFECTED< 2.3.3SAFE ✓≥ 2.3.3
Updated Aug 21, 2026View on NVD →
Detail

The Button Generator WordPress plugin is an admin menu page that allows website owners to generate customizable buttons for various purposes. This plugin is used to easily create buttons that can redirect users to other pages or perform specific actions on the website. In just a few clicks, users can generate buttons with text, colors, links, and more.

However, the Button Generator WordPress plugin before version 2.3.3 was found to have a serious vulnerability known as CVE-2016-1000152. This vulnerability allows attackers to include arbitrary files with PHP extensions, data:// or http:// protocols, through a CSRF RCE vulnerability. As a result, this allows attackers to execute remote code on the victim's machine, granting them complete control over the website and the underlying server.

When exploited, this vulnerability can lead to disastrous consequences for website owners. Attackers can gain access to sensitive information stored in the server and use it for malicious purposes, such as stealing confidential data or infecting the website with malware. They could also bypass any authentication mechanisms, add malicious content, deface the website, or use it to conduct attacks on other systems.

At s4e.io, we offer pro features that can help website owners quickly and easily identify vulnerabilities in their digital assets. Our platform offers comprehensive security scans, automated vulnerability assessments, and real-time alerts to ensure that website owners can mitigate any threats before they cause harm. Stay safe and secure, and let s4e.io help you keep your website protected.

 

REFERENCES

Solution Advice

Fortunately, there are several precautions that website owners can take to protect against this vulnerability, such as:

  • Updating the Button Generator plugin to the latest version (2.3.3 or newer).
  • Disabling any unused plugins or themes on the website.
  • Conducting regular security audits to identify any vulnerabilities in the site.
  • Implementing a web application firewall (WAF) to block any malicious requests.
  • Encrypting all data transmitted between the server and the user's machine using SSL/TLS.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.