S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-25003 Scanner

CVE-2021-25003 scanner - Remote Code Execution (RCE) vulnerability in WPCargo Track & Trace plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.3k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-25003
9.8
CVSS

The WPCargo Track & Trace WordPress plugin before 6.9.0 contains a file which could allow unauthenticated attackers to write a PHP file anywhere on the web server, leading to RCE

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
WPCargo Track & Trace
AFFECTED< 6.9.0SAFE ✓≥ 6.9.0
Updated Aug 21, 2026View on NVD →
Detail

The WPCargo Track & Trace WordPress plugin is an application designed to enable businesses to manage their cargo delivery and logistical needs through their WordPress-powered website. This intuitive plugin is an ideal choice for e-commerce businesses and shipping companies that rely on reliable and efficient transportation management systems. Utilizing this powerful tool, companies can support their logistics operations, track their shipments, manage their orders, receive online payments, and stay informed about customer deliveries. The WPCargo Track & Trace plugin is a valuable asset for online businesses that require professional and reliable transportation and logistics management systems.

Recently, a critical vulnerability has been detected in the WPCargo Track & Trace WordPress plugin, particularly the version 6.9.0 and earlier. This vulnerability is identified as the CVE-2021-25003. It poses a serious security threat to the plugin users as it could be exploited by an unauthenticated attacker to write a PHP file anywhere on the web server, potentially leading to remote code execution (RCE). Attackers could use this exploit to execute arbitrary code, install malware, steal sensitive data, or even take control of the server.

Exploiting this vulnerability could cause significant damage to businesses. An attacker could potentially steal sensitive data, customer's information, and gain unauthorized access to the server, causing business downtime and loss of revenue. Moreover, the attacker could use the same RCE method to launch further attacks on other connected systems, potentially causing even more harm.

It is high time that companies take the necessary precautions to protect their digital assets. The s4e.io platform offers critical services to ensure that businesses' digital assets remain secure. Subscribing to their Pro features will enable you to stay informed about vulnerabilities in your digital assets, and provide insight into threat detection, security analytics, and recommendations for the appropriate course of action in the event of a vulnerability or cyberattack. Protecting your digital assets should be a top priority, and partnering with s4e.io ensures the peace of mind required.

 

REFERENCES

Solution Advice

Fortunately, there are several precautions that users can take to protect against this vulnerability. Here are some recommended measures:

  • Update the WPCargo Track & Trace plugin to the latest version.
  • Limit the plugin's access control to authorized users and restrict the plugin's file upload feature.
  • Add additional lines of code to the .htaccess file to restrict the use of PHP files.
  • Install a web application firewall (WAF) to block any unauthorized access attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.