S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Feb 23, 2024

CVE-2021-24862 Scanner

CVE-2021-24862 scanner - SQL Injection (SQLi) vulnerability in WordPress RegistrationMagic plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.7k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-24862
7.2
CVSS

The RegistrationMagic WordPress plugin before 5.0.1.6 does not escape user input in its rm_chronos_ajax AJAX action before using it in a SQL statement when duplicating tasks in batches, which could lead to a SQL injection issue

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
RegistrationMagic – Custom Registration Forms, User Registration and User Login Plugin
AFFECTED< 5.0.1.6SAFE ✓≥ 5.0.1.6
Updated Aug 21, 2026View on NVD →
Detail

Vulnerability Overview

CVE-2021-24862 exposes WordPress sites to SQL injection attacks via the RegistrationMagic plugin. It specifically impacts the functionality related to duplicating tasks in batches, where user input is not properly sanitized before being used in SQL queries.

Vulnerability Details

The issue is found in the 'rm_chronos_ajax' AJAX action, where parameters related to task duplication are not adequately escaped. This flaw allows authenticated users, especially those with administrative access, to inject arbitrary SQL commands, potentially leading to data breaches or unauthorized administrative actions.

Possible Effects

Exploiting CVE-2021-24862 could result in:

  • Unauthorized access to sensitive database information.
  • Modification or deletion of crucial data, affecting site integrity.
  • Execution of unauthorized administrative operations.

Why Choose S4E

At S4E, we prioritize your digital safety with cutting-edge vulnerability scanning tools and expert insights. By choosing us, you gain:

  • Real-time alerts on vulnerabilities like CVE-2021-24862.
  • Customized remediation strategies to protect your WordPress site.
  • Comprehensive security assessments to prevent future exploits. Secure your online presence with S4E and stay one step ahead of cyber threats.

References

Solution Advice
  • Update Immediately: Upgrade the RegistrationMagic plugin to version 5.0.1.6 or later.
  • Review User Permissions: Ensure that only trusted users have administrative privileges.
  • Monitor Database Access: Regularly check for unusual database queries or unauthorized access attempts.
  • Security Plugins: Utilize WordPress security plugins to monitor and block suspicious activities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-24862 scanner - SQL Injection (SQLi) vulnerability in WordPress RegistrationMagic plugin for WordPress | S4E