S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2019-6112 Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in Sell Media plugin for WordPress affects v. 2.4.1.

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.2k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2019-6112
6.1
CVSS

A Cross-site scripting (XSS) vulnerability in /inc/class-search.php in the Sell Media plugin v2.4.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the keyword parameter (aka $search_term or the Search field).

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Sell Media Plugin for WordPress is a popular plugin that allows photographers, artists, and graphic designers to create an online store on their WordPress website and sell their digital products such as photos, videos, and audio files. With its user-friendly interface, users can easily upload their digital goods, set their prices, and manage their sales from one central location.

However, the plugin was found to contain a severe vulnerability, CVE-2019-6112, that could potentially put the website at risk. This vulnerability can be exploited by attackers using Cross-site scripting (XSS) techniques to inject arbitrary web script or HTML via the keyword parameter in the search field.

Exploiting this vulnerability can lead to several serious consequences such as stealing users' sensitive information, hijacking their accounts, spreading malware, and gaining unauthorized access to the website's backend. Attackers can also use this vulnerability to redirect the user to a malicious site and perform phishing attacks, which puts the user's data and personal information at risk.

In conclusion, it is essential for website owners to stay informed about the vulnerabilities and risks affecting their digital assets. The pro features of s4e.io offer a comprehensive and effective solution to identify, assess, and manage the vulnerabilities and risks that may affect your online business. By using the s4e.io service, you can be confident in the security of your digital assets and focus on growing your business.

 

REFERENCES

Solution Advice

To protect against CVE-2019-6112, users of the Sell Media Plugin for WordPress should consider taking the following precautions:

  • Install the latest version of the plugin as soon as updates are released.
  • Regularly scan your website for vulnerabilities using a vulnerability scanner.
  • Implement a web application firewall (WAF) to block malicious requests and traffic.
  • Use secure passwords and two-factor authentication to protect your user accounts.
  • Limit the use of plugins and add-ons that are not necessary to your website's functionality.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.