S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-24926 Scanner

CVE-2021-24926 scanner - Cross-Site Scripting (XSS) vulnerability in Domain Check plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-24926
6.1
CVSS

The Domain Check WordPress plugin before 1.0.17 does not sanitise and escape the domain parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting issue

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

The Domain Check plugin for WordPress is a tool designed to provide website owners with a simple and effective way to check the availability of domains. This plugin is commonly used by WordPress-powered websites to streamline the process of domain name registration and management. Users can easily check the availability of a desired domain name, and if it's available, register it directly from the WordPress dashboard. Additionally, users can also track the availability of various domain names and receive notifications if any become available.

Recently, a vulnerability in the Domain Check plugin, identified as CVE-2021-24926, has been detected. This vulnerability occurs due to the lack of sanitisation and escape of the domain parameter before it's outputted on the page. As a result, attackers may inject malicious code into the website through the domain parameter, leading to a Reflected Cross-Site Scripting (XSS) issue.

When exploited, this vulnerability can allow attackers to execute potentially harmful scripts on the website, leading to various malicious activities such as data theft and website defacement. Furthermore, the sensitive information of both website owners and users may be compromised.

Finally, to ensure the safety of their digital assets, website owners can turn to s4e.io for expert guidance. This platform provides advanced security features that make the process of identifying and patching vulnerabilities much easier. With s4e.io, website owners can quickly learn about any potential threats and ensure the safety of their online presence. Don't wait any longer, secure your website today with s4e.io!

 

REFERENCES

Solution Advice

To protect against this vulnerability, website owners can take the following precautions:

  • Install the latest version of the Domain Check plugin to receive patches that address this vulnerability
  • Keep all WordPress plugins updated to prevent cybercriminals from exploiting any known vulnerabilities.
  • Only allow trusted users to access the WordPress dashboard and sensitive areas of the website.
  • Regularly scan the website for vulnerabilities using security tools provided by reliable vendors.
  • Use a web application firewall (WAF) to filter out malicious traffic and protect the website against common attacks like XSS.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-24926 scanner - Cross-Site Scripting (XSS) vulnerability in Domain Check plugin for WordPress | S4E