CVE-2021-34640
Securimage-WP-Fixed <= 3.5.4 Reflected Cross-Site Scripting
Record summary
CVE-2021-34640 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
The Securimage-WP-Fixed WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['PHP_SELF'] in the ~/securimage-wp.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 3.5.4.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated May 23, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Securimage-WP-FixedBrowse Securimage-WP-Fixed / Securimage-WP-Fixed | CVE List | 3.5.4 to ≤ 3.5.4 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMWordPress Securimage-WP-Fixed <=3.5.4 - Cross-Site ScriptingCVSS 6.1
WordPress Securimage-WP-Fixed plugin 3.5.4 and prior contains a cross-site scripting vulnerability due to the use of $_SERVER['PHP_SELF'] in the ~/securimage-wp.php file, which allows attackers to inject arbitrary web scripts.
Impact
Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into the affected website, potentially leading to session hijacking, defacement, or theft of sensitive information.
Remediation
Update the Securimage-WP-Fixed plugin to version 3.5.4 or later to mitigate the vulnerability.
Source: ProjectDiscovery