S4E just found a high top 10 tcp port service scan
medium·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2021-24316 Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in Mediumish theme for Wordpress affects v. through 1.0.47.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.1k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-24316
6.1
CVSS

The search feature of the Mediumish WordPress theme through 1.0.47 does not properly sanitise it's 's' GET parameter before output it back the page, leading to the Cross-SIte Scripting issue.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Mediumishby WowThemes
1.0.47
Updated Aug 21, 2026View on NVD →
Detail

Mediumish is a popular WordPress theme that is commonly used for blogs and news websites. This theme is known for its sleek and modern design that attracts a considerable number of users. It is widely used by content creators, bloggers, and publishers for showcasing their content in an alluring manner.

CVE-2021-24316 is a critical vulnerability detected in the Mediumish WordPress theme. This vulnerability is caused by the theme’s search feature which fails to sanitize the ‘s’ GET parameter before outputting it back to the page. This makes it possible for attackers to inject malicious script codes into web pages through the search box.

When exploited, this vulnerability can result in a full-blown Cross-site Scripting (XSS) attack. The attacker can execute arbitrary code within the web browser of the victim, which may result in significant damage. The attacker can gain unauthorized access to sensitive data, steal user login credentials, and initiate other attacks that compromise the integrity of the affected system.

The pro features of s4e.io platform provide an easy and efficient way to learn about vulnerabilities in digital assets. With s4e.io, users can easily scan their websites for vulnerabilities and receive timely alerts whenever a vulnerability is detected. This platform is user-friendly and supports a wide range of CMS including WordPress, Joomla, Drupal, and Magento. With s4e.io, businesses can enjoy peace of mind knowing that their digital assets are secure and protected.

 

REFERENCES

 

Solution Advice

To protect against this vulnerability, it is recommended that users take the following precautions:

  • Update the Mediumish theme to the latest version
  • Disable the search feature until the theme is updated
  • Use a well-configured Web Application Firewall (WAF)
  • Regularly back up the website in case of a breach
  • Educate the website administrator and users on best security practices

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.