S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2021-24176 Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in JH 404 Logger plugin for Wordpress affects v. through 1.1.

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.9k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-24176
5.4
CVSS

The JH 404 Logger WordPress plugin through 1.1 doesn't sanitise the referer and path of 404 pages, when they are output in the dashboard, which leads to executing arbitrary JavaScript code in the WordPress dashboard.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
JH 404 Logger
1.1
Updated Aug 21, 2026View on NVD →
Detail

The JH 404 Logger is a WordPress plugin used to track and monitor 404 pages on your website. It allows website owners to keep an eye on broken links and missing pages, providing valuable insights for website maintenance and optimization. The plugin is designed to help website owners improve their user experience by identifying and fixing any potential issues on their site.

However, despite its benefits, the JH 404 Logger WordPress plugin through version 1.1 is susceptible to a severe vulnerability known as CVE-2021-24176. This vulnerability stems from the plugin's failure to sanitise the referer and path of 404 pages, leaving open the possibility for malicious actors to execute arbitrary JavaScript code in the WordPress dashboard.

Exploiting this vulnerability can lead to severe consequences for website owners. The attacker can execute any JavaScript code in the WordPress dashboard, leading to a complete compromise of the site. This includes taking control of the site and its database, modifying or deleting content, and injecting malicious code or scripts. The consequences can be severe, resulting in financial loss, reputational damage, and even legal action in some cases.

In conclusion, the JH 404 Logger plugin is a powerful tool for website owners, allowing them to monitor and optimize their sites effectively. However, the CVE-2021-24176 vulnerability poses a severe risk to website owners using this plugin. It is essential to take comprehensive precautions to mitigate the risk of exploitation and protect your website from cyberattacks. s4e.io offers valuable insights and resources necessary to understand and protect your digital assets from vulnerabilities. By leveraging the pro features available on their platform, website owners can safeguard their websites quickly and efficiently.

 

REFERENCES

Solution Advice

To protect against this vulnerability, website owners using the JH 404 Logger plugin should take extensive precautions. Here are some of the ways to safeguard your website:

  • Remove the JH 404 Logger plugin if you're not using it. This can instantly mitigate the risk of exploitation.
  • Update your plugin to the latest version available from the vendor.
  • Limit access to the WordPress dashboard to only authorized personnel.
  • Regularly monitor your website for any suspicious activity and report any anomalies promptly.
  • Employ other website security measures such as firewalls and malware scanners.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-24176 scanner - Cross-Site Scripting (XSS) vulnerability in JH 404 Logger plugin for Wordpress | S4E