Record summary

CVE-2021-34640 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

The Securimage-WP-Fixed WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['PHP_SELF'] in the ~/securimage-wp.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 3.5.4.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated May 23, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List3.5.4 to ≤ 3.5.4affected

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress Securimage-WP-Fixed <=3.5.4 - Cross-Site ScriptingCVSS 6.1

WordPress Securimage-WP-Fixed plugin 3.5.4 and prior contains a cross-site scripting vulnerability due to the use of $_SERVER['PHP_SELF'] in the ~/securimage-wp.php file, which allows attackers to inject arbitrary web scripts.

Impact

Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into the affected website, potentially leading to session hijacking, defacement, or theft of sensitive information.

Remediation

Update the Securimage-WP-Fixed plugin to version 3.5.4 or later to mitigate the vulnerability.

WeaknessesCWE-79
AuthorsdhiyaneshDK
Template tagscve2021cvewpscanwordpresswp-pluginauthenticatedsecurimage-wp-fixed_projectvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:securimage-wp-fixed_project:securimage-wp-fixed:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

3