CVE-2021-34640
published 2021-08-11CVE-2021-34640: The Securimage-WP-Fixed WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['PHP_SELF'] in the ~/securimage-wp.php file…
PriorityP337medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EXPLOIT
EPSS
2.22%
80.5th percentile
The Securimage-WP-Fixed WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['PHP_SELF'] in the ~/securimage-wp.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 3.5.4.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| securimage-wp-fixed | securimage-wp-fixed | 3.5.4 – 3.5.4 | — |
| securimage-wp-fixed_project | securimage-wp-fixed | <= 3.5.4 | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Nuclei
WordPress Securimage-WP-Fixed <=3.5.4 - Cross-Site Scripting
nuclei·CVSS 6.1
CVE-2021-34640 [MEDIUM] WordPress Securimage-WP-Fixed <=3.5.4 - Cross-Site Scripting
WordPress Securimage-WP-Fixed alert(document.domain)/script%3E?page=securimage-wp-options%2F HTTP/1.1
Host: {{Hostname}}
matchers-condition: and
matchers:
- type: word
part: body
words:
- 'alert(document.domain)'
- type: word
part: header
words:
- "text/html"
- type: status
status:
- 200
# digest: 4b0a00483046022100e2c2d36d08b21bd5ea312a0e70ae4cd93f5dc966992c6e83b0f195cf5cd908630221008699c1d0dcd247666b3535f5b723e733ecd603a1d4939bf89448e459c88d81f4:922c64590222798bb761d5b6d8e72950
No writeups or analysis indexed.
https://plugins.trac.wordpress.org/browser/securimage-wp-fixed/trunk/securimage-wp.php#L628https://www.wordfence.com/vulnerability-advisories/#CVE-2021-34640https://plugins.trac.wordpress.org/browser/securimage-wp-fixed/trunk/securimage-wp.php#L628https://www.wordfence.com/vulnerability-advisories/#CVE-2021-34640
2021-08-11
Published