S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-25104 Scanner

CVE-2021-25104 scanner - Cross-Site Scripting (XSS) vulnerability in Ocean Extra plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.3k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-25104
6.1
CVSS

The Ocean Extra WordPress plugin before 1.9.5 does not escape generated links which are then used when the OceanWP is active, leading to a Reflected Cross-Site Scripting issue

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Ocean Extra
AFFECTED< 1.9.5SAFE ✓≥ 1.9.5
Updated Aug 21, 2026View on NVD →
Detail

The Ocean Extra WordPress plugin is a powerful tool that provides additional functionalities and customization options for websites built on the popular blogging platform. This plugin is designed specifically to be used in conjunction with the OceanWP theme and offers a wide range of features, including custom widgets, sticky header options, and more. With its user-friendly interface and extensive capabilities, the Ocean Extra plugin has become a go-to for many website owners who want to enhance their site's performance and functionality.

Unfortunately, with the introduction of the CVE-2021-25104 vulnerability, the Ocean Extra plugin has become vulnerable to cyberattacks. This Reflected Cross-Site Scripting issue occurs due to the plugin's failure to escape generated links, leaving the plugin open to exploitation. This means that attackers can inject malicious codes into the website and potentially gain control over its admin privileges and data.

If this vulnerability is exploited, it can lead to serious consequences for website owners. The attacker can hijack cookies, steal user data, and inject other harmful code which can damage the integrity of the site. Additionally, the attacker can gain control over the site and use it to distribute phishing and malware attacks to the users visiting the site.

As a final note, it is important to remember that security is a continuous process and website owners need to be diligent in monitoring and maintaining their site's security. This is where the pro features of the s4e.io platform can be invaluable. By using this platform, website owners can stay up-to-date on the latest security threats and quickly learn about vulnerabilities in their digital assets. This can give them the peace of mind needed to focus on growing their online presence without worrying about risking their website's security.

 

REFERENCES

Solution Advice

To protect against the vulnerability, there are several precautions that can be taken. These are:

  • Update the Ocean Extra plugin to the latest version available.
  • Install a security plugin such as WordFence or iThemes to prevent unwanted login attempts and block malicious traffic.
  • Regularly scan the website for vulnerabilities using website scanners like Qualys and Acunetix.
  • Educate all website users, including site administrators and content creators, about website security best practices and the dangers of phishing and malware attacks.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-25104 scanner - Cross-Site Scripting (XSS) vulnerability in Ocean Extra plugin for WordPress | S4E