S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-24406 Scanner

Detects 'Open Redirect' vulnerability in wpForo Forum plugin for WordPress affects v. before 1.9.7.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.4k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-24406
6.1
CVSS

The wpForo Forum WordPress plugin before 1.9.7 did not validate the redirect_to parameter in the login form of the forum, leading to an open redirect issue after a successful login. Such issue could allow an attacker to induce a user to use a login URL redirecting to a website under their control and being a replica of the legitimate one, asking them to re-enter their credentials (which will then in the attacker hands)

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
wpForo Forumby gVectors Team
AFFECTED< 1.9.7SAFE ✓≥ 1.9.7
Updated Aug 21, 2026View on NVD →
Detail

The wpForo Forum is a well-known WordPress plugin designed for creating online forums on WordPress websites. It is primarily used to establish online communities where members can engage in discussions and share ideas on various topics of interest. The plugin is simple to install and comes with plenty of features, making it an ideal choice for website owners looking to create an interactive discussion platform.

One of the most critical issues detected in the wpForo Forum plugin is the CVE-2021-24406 vulnerability. This vulnerability allowed attackers to exploit the login form's open redirect problem by inducing unsuspecting users to click and follow an attacker's malicious URL. Subsequently, users would be redirected to a fake login page that appears legitimate but runs on an attacker's server. Unsuspecting users would then enter their login credentials, believing they are logging in to the actual forum site, and unknowingly handing their data over to the attacker.

Exploitation of the CVE-2021-24406 vulnerability could lead to severe privacy and security concerns for website owners and users of the wpForo Forum plugin. Suppose an attacker successfully steals user credentials. In that case, they could use the information obtained to gain unauthorized access to users' personal or sensitive data, causing damage to both the website and the user's reputation. There could be legal implications for the website owner as well, for failing to secure their site.

s4e.io is an excellent resource for website owners to stay informed about the latest security vulnerabilities affecting their digital assets. The platform's pro features enable users to quickly and easily evaluate their sites for any security risks and receive customized recommendations on how to mitigate those risks. By taking advantage of these features, website owners can rest easy, knowing they have taken the necessary steps to protect their business and users' confidential data.

 

REFERENCES

Solution Advice

The following precautions can be taken to protect against the CVE-2021-24406 vulnerability:

  • Update the wpForo Forum plugin to the latest version
  • Be cautious when clicking on links and inspect them before clicking
  • Never enter login credentials on a page that looks suspicious
  • Use two-factor authentication to add an extra layer of protection to your account
  • Educate your community of users on safe browsing habits and the importance of cybersecurity.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-24406 scanner - Open Redirect vulnerability in wpForo Forum plugin for WordPress | S4E