S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 8, 2024

CVE-2021-39312 Scanner

CVE-2021-39312 scanner - Improper Access Control vulnerability in True Ranker plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.1k
Times Used
continuous scan runs
5.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-39312
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

The True Ranker plugin <= 2.2.2 for WordPress allows arbitrary files, including sensitive configuration files such as wp-config.php, to be accessed via the src parameter found in the ~/admin/vendor/datatables/examples/resources/examples.php file.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
True Rankerby True Ranker
2.2.2
Updated Aug 21, 2026View on NVD →
Detail

The True Ranker plugin is a WordPress plugin that is used to track website rankings and performance. It is a crucial tool for website owners, SEO professionals, and digital marketers who want to monitor and analyze their website’s search engine visibility. The plugin provides comprehensive reports, custom alerts, and recommendations to help improve website ranking and traffic.

Recently, researchers have discovered a critical security vulnerability in the True Ranker plugin, identified as CVE-2021-39312. This vulnerability allows an attacker to gain access to sensitive configuration files, including wp-config.php, by manipulating the src parameter found in the examples.php file.

Exploiting this vulnerability can have significant consequences for website owners. By gaining access to the configuration files, an attacker can potentially take control of the website, steal sensitive data, and carry out malicious activities such as injecting malware or defacing the website.

Those who are concerned about the security of their digital assets can benefit from the pro features of the s4e.io platform. This platform offers comprehensive and accurate vulnerability assessments for websites, web applications, and other digital assets. By using this platform, website owners can quickly identify, prioritize, and fix security issues to prevent cyber attacks and data breaches. Don’t wait until it’s too late – take action now to protect your website and digital assets!

 

REFERENCES

Solution Advice

To protect against this vulnerability, website owners are advised to take the necessary precautions, including:

  • Updating to the latest version of the True Ranker plugin as soon as possible
  • Restricting file permissions to limit access to sensitive files
  • Implementing access control mechanisms to limit access to the plugin’s files and directories
  • Monitoring file changes and activities on the website
  • Using additional security measures, such as firewalls and intrusion detection systems

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-39312 scanner - Improper Access Control vulnerability in True Ranker plugin for WordPress | S4E