S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-33851 Scanner

CVE-2021-33851 scanner - Cross-Site Scripting (XSS) vulnerability in Customize Login Image plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-33851
5.4
CVSS

A cross-site scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user's browser and can use an application as the vehicle for the attack. The XSS payload given in the "Custom logo link" executes whenever the user opens the Settings Page of the "Customize Login Image" Plugin.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
WordPress Customize Login Image Pluginby n/a
Version 3.4
Updated Aug 21, 2026View on NVD →
Detail

Customize Login Image plugin for WordPress is a popular tool that enables website owners to add a custom logo, background, and colors to their login page. With its easy-to-use interface and intuitive settings, it's no wonder that this plugin is a favorite amongst WordPress users. The plugin is designed to enhance the user experience of the site by providing an attractive and cohesive design throughout all pages, including the login page.

However, the plugin's security was recently compromised by a vulnerability known as CVE-2021-33851. This vulnerability allowed attackers to execute arbitrary JavaScript code within a user's browser, potentially compromising their sensitive information. It was discovered that this vulnerability was present in the plugin's "Custom logo link" feature, which executes on the Settings Page of the Customize Login Image Plugin.

Exploitation of this vulnerability can lead to a range of negative consequences. For example, an attacker could use it to steal sensitive data such as login credentials and payment information from users. In addition, they could manipulate the user's browser to execute malicious code that could take over their entire system or redirect them to a malicious website.

With the pro features of the s4e.io platform, website owners can easily and quickly learn about vulnerabilities in their digital assets. This service provides comprehensive security testing and scanning solutions that can identify and remediate any vulnerabilities present in the Customize Login Image plugin or any other WordPress plugin. Website owners can rest assured that their digital assets are secure with the help of this powerful platform.

 

REFERENCES

Solution Advice

Fortunately, there are several precautions that website owners can take to protect themselves against this vulnerability. These include:

  • Keeping the plugin up to date with the latest version.
  • Avoiding the use of third-party scripts or links in the plugin's settings.
  • Running regular security scans on their website to detect any potential vulnerabilities.
  • Implementing a Web Application Firewall (WAF) to block malicious traffic.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-33851 scanner - Cross-Site Scripting (XSS) vulnerability in Customize Login Image plugin for WordPress | S4E