S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-24495 Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in Marmoset Viewer plugin for WordPress affects v. before 1.9.3.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.2k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-24495
6.1
CVSS

The Marmoset Viewer WordPress plugin before 1.9.3 does not property sanitize, validate or escape the 'id' parameter before outputting back in the page, leading to a reflected Cross-Site Scripting issue.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Marmoset Viewer
AFFECTED< 1.9.3SAFE ✓≥ 1.9.3
Updated Aug 21, 2026View on NVD →
Detail

The Marmoset Viewer is a plugin for WordPress used for displaying interactive 3D models on websites. It provides an easy way of showcasing product designs, architectural plans, or even detailed scientific models. The plugin is widely used in the design and tech industry, making it an incredibly useful tool for many businesses.

Recently, a vulnerability has been detected in the Marmoset Viewer plugin for WordPress. The CVE-2021-24495 vulnerability allows attackers to exploit the plugin's failure to sanitize, validate or escape the 'id' parameter before outputting it on the page, leading to a reflected Cross-Site Scripting issue. This means that attackers can execute malicious scripts onto a user's browser, leading to data theft, such as sensitive information like passwords or even financial details.

When exploited, the CVE-2021-24495 vulnerability can be quickly escalated and lead to irrevocable damage to businesses and organizations. Attackers can gain unauthorized access to the site, causing significant problems such as data breaches, website defacement, and even service disruptions. This puts both the business and its customers at considerable risk.

In conclusion, vulnerabilities such as CVE-2021-24495 can lead to catastrophic results if not addressed. It's essential to take precautionary measures such as those outlined above, to reduce the risk of such an attack. Businesses can make use of s4e.io's pro features to learn and stay up to date about the vulnerabilities present in their digital assets. With proper measures in place, businesses can significantly reduce the risk of attacks and protect their assets, customers, and reputation.

 

REFERENCES

Solution Advice

However, businesses can take precautionary measures to reduce the risk of such an attack. Here are some precautions that can be followed:

  • Upgrade to the latest version of the Marmoset Viewer plugin for WordPress, which has fixed this vulnerability.
  • Limit access to internal servers, networks, and databases.
  • Implement two-factor authentication to prevent unauthorized access.
  • Use a web application firewall (WAF) to detect and block malicious traffic.
  • Conduct regular security audits to detect and prevent any vulnerabilities on the website.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-24495 scanner - Cross-Site Scripting (XSS) vulnerability in Marmoset Viewer plugin for WordPress | S4E