Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- \ \ / / \ / __|
- \ \ /\ / /| |) | (_ _ _ _ ®
- \ \/ \/ / | _/ _ \ / |/ ` | ' \
- \ /\ / | | __) | (| (| | | | |
- \/ \/ || |_/ ___|_,|| ||
- WordPress Security Scanner by the WPScan Team
- Version 3.8.27
- Sponsored by Automattic - https://automattic.com/
- @WPScan, @ethicalhack3r, @erwan_lr, @firefart
- [i] It seems like you have not updated the database for some time.
- [?] Do you want to update now? [Y]es [N]o, default: [N]y
- [i] Updating the Database ...
- [i] Update completed.
- [+] URL: https://research.23andme.com/ [104.16.182.73][+] Started: Fri Jan 3 01:12:34 2025
- Interesting Finding(s):
- [+] Headers
- | Interesting Entries:
- | - x-amz-server-side-encryption: AES256
- | - via: 1.1 6022b3c50d8e5cf8002901246f988028.cloudfront.net (CloudFront)
- | - x-amz-cf-pop: MRS53-P2
- | - x-amz-cf-id: zNEThCsknHwr1Hz9kUB1ype_3dCgLDPIFcnNOzdXl5Ok750zqYWFww==
- | - cf-cache-status: DYNAMIC
- | - server: cloudflare
- | - cf-ray: 8fc0d685fa394eb9-JNB
- | Found By: Headers (Passive Detection)
- | Confidence: 100%
- [i] The WordPress version could not be detected.
- [+] WordPress theme in use: 23andMe-Medical
- | Location: https://research.23andme.com/wp-content/themes/23andMe-Medical/
- | Style URL: https://research.23andme.com/wp-content/themes/23andMe-Medical/style.css
- |
- | Found By: Urls In Homepage (Passive Detection)
- |
- | The version could not be determined.
- [+] Enumerating Vulnerable Plugins (via Passive Methods)
- [+] Checking Plugin Versions (via Passive Methods)
- [i] Plugin(s) Identified:
- [+] contact-form-7
- | Location: https://research.23andme.com/wp-content/plugins/contact-form-7/
- | Last Updated: 2024-12-22T05:03:00.000Z
- | [!] The version is out of date, the latest version is 6.0.2
- |
- | Found By: Urls In Homepage (Passive Detection)
- |
- | [!] 4 vulnerabilities identified:
- |
- | [!] Title: Contact Form 7 < 5.3.2 - Unrestricted File Upload
- | Fixed in: 5.3.2
- | References:
- | - https://wpscan.com/vulnerability/7391118e-eef5-4ff8-a8ea-f6b65f442c63
- | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-35489
- | - https://www.getastra.com/blog/911/plugin-exploit/contact-form-7-unrestricted-file-upload-vulnerability/
- | - https://www.jinsonvarghese.com/unrestricted-file-upload-in-contact-form-7/
- | - https://contactform7.com/2020/12/17/contact-form-7-532/#more-38314
- |
- | [!] Title: Contact Form 7 < 5.8.4 - Authenticated (Editor+) Arbitrary File Upload
- | Fixed in: 5.8.4
- | References:
- | - https://wpscan.com/vulnerability/70e21d9a-b1e6-4083-bcd3-7c1c13fd5382
- | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-6449
- | - https://www.wordfence.com/threat-intel/vulnerabilities/id/5d7fb020-6acb-445e-a46b-bdb5aaf8f2b6
- |
- | [!] Title: Contact Form 7 < 5.9.2 - Reflected Cross-Site Scripting
- | Fixed in: 5.9.2
- | References:
- | - https://wpscan.com/vulnerability/1c070a2c-2ab0-43bf-b10b-6575709918bc
- | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-2242
- | - https://www.wordfence.com/threat-intel/vulnerabilities/id/d5bf4972-424a-4470-a0bc-7dcc95378e0e
- |
- | [!] Title: Contact Form 7 < 5.9.5 - Unauthenticated Open Redirect
- | Fixed in: 5.9.5
- | References:
- | - https://wpscan.com/vulnerability/8bdcdb5a-9026-4157-8592-345df8fb1a17
- | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-4704
- |
- | Version: 5.2 (20% confidence)
- | Found By: Query Parameter (Passive Detection)
- | - https://research.23andme.com/wp-content/plugins/contact-form-7/includes/css/styles.css?ver=5.2
- | - https://research.23andme.com/wp-content/plugins/contact-form-7/includes/js/scripts.js?ver=5.2
- [+] js_composer
- | Location: https://research.23andme.com/wp-content/plugins/js_composer/
- | Last Updated: 2024-12-11T19:40:45.000Z
- | [!] The version is out of date, the latest version is 8.1
- |
- | Found By: Urls In Homepage (Passive Detection)
- | Confirmed By: Body Tag (Passive Detection)
- |
- | [!] 9 vulnerabilities identified:
- |
- | [!] Title: WPBakery Page Builder < 6.4.1 - Authenticated Stored Cross-Site Scripting (XSS)
- | Fixed in: 6.4.1
- | References:
- | - https://wpscan.com/vulnerability/11285589-1b22-4ec0-adfc-f2add70db4d7
- | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-28650
- | - https://www.wordfence.com/blog/2020/10/vulnerability-exposes-over-4-million-sites-using-wpbakery/
- |
- | [!] Title: WPBakery Page Builder < 6.13.0 - Contributor+ Stored XSS
- | Fixed in: 6.13.0
- | References:
- | - https://wpscan.com/vulnerability/ee99521d-be25-41ef-8988-5cfd66e9c5ca
- | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-31213
- |
- | [!] Title: WPBakery Visual Composer < 7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Title tag attribute
- | Fixed in: 7.6
- | References:
- | - https://wpscan.com/vulnerability/787a71f8-1179-4442-9441-87fbe83a7e67
- | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-1841
- | - https://www.wordfence.com/threat-intel/vulnerabilities/id/34d21418-4faf-40bf-a960-79482a592722
- |
- | [!] Title: WPBakery Visual Composer < 7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Heading tag attribute
- | Fixed in: 7.6
- | References:
- | - https://wpscan.com/vulnerability/8ebfad34-7b46-4783-9fad-c96ab4f4c737
- | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-1842
- | - https://www.wordfence.com/threat-intel/vulnerabilities/id/674e6722-d293-4572-80bf-984e74c3e33f
- |
- | [!] Title: WPBakery Visual Composer < 7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button onclick attribute
- | Fixed in: 7.6
- | References:
- | - https://wpscan.com/vulnerability/b87926cd-0fe0-49df-8c61-9df1363a67a8
- | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-1805
- | - https://www.wordfence.com/threat-intel/vulnerabilities/id/7a571386-fae1-4a56-8567-9d3e23249de1
- |
- | [!] Title: WPBakery Visual Composer < 7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Author
- | Fixed in: 7.6
- | References:
- | - https://wpscan.com/vulnerability/b41c2343-3be4-4bd9-ae5d-69ae96ba23ae
- | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-1840
- | - https://www.wordfence.com/threat-intel/vulnerabilities/id/cb8ecbbc-ada9-4887-92e6-25a587ecfb84
- |
- | [!] Title: WPBakery Page Builder < 7.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via VC Single Image link attribute
- | Fixed in: 7.7
- | References:
- | - https://wpscan.com/vulnerability/3b067a13-ee58-44c9-80af-ae04af6256c8
- | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5265
- | - https://www.wordfence.com/threat-intel/vulnerabilities/id/35a5114e-5c5f-4003-8bb3-77243ffbac1a
- |
- | [!] Title: WPBakery < 7.8 - Authenticated (Author+) Stored Cross-Site Scripting
- | Fixed in: 7.8
- | References:
- | - https://wpscan.com/vulnerability/992e5d47-e290-420a-adf8-f552a929e51d
- | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5708
- | - https://www.wordfence.com/threat-intel/vulnerabilities/id/23ff12f0-eb9d-4bb3-8db0-0e794c0f0594
- |
- | [!] Title: WPBakery < 7.8 - Authenticated (Author+) Local File Inclusion
- | Fixed in: 7.8
- | References:
- | - https://wpscan.com/vulnerability/6e3e1944-67f7-405e-ae4f-f0ab8c6c9acd
- | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5709
- | - https://www.wordfence.com/threat-intel/vulnerabilities/id/7fad30c8-fd8a-4cf2-a3aa-16a374231b87
- |
- | Version: 6.1 (80% confidence)
- | Found By: Body Tag (Passive Detection)
- | - https://research.23andme.com/, Match: 'js-comp-ver-6.1'
- | Confirmed By: Query Parameter (Passive Detection)
- | - https://research.23andme.com/wp-content/plugins/js_composer/assets/css/js_composer.min.css?ver=6.1
- | - https://research.23andme.com/wp-content/plugins/js_composer/assets/js/dist/js_composer_front.min.js?ver=6.1
- [+] wpcf7-redirect
- | Location: https://research.23andme.com/wp-content/plugins/wpcf7-redirect/
- | Latest Version: 3.1.9
- | Last Updated: 2024-11-12T22:31:00.000Z
- |
- | Found By: Urls In Homepage (Passive Detection)
- |
- | [!] 10 vulnerabilities identified:
- |
- | [!] Title: Redirection for Contact Form 7 < 2.3.4 - Unauthenticated Arbitrary Nonce Generation
- | Fixed in: 2.3.4
- | References:
- | - https://wpscan.com/vulnerability/99f30604-d62b-4e30-afcd-b482f8d66413
- | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-24278
- | - https://www.wordfence.com/blog/2021/04/severe-vulnerabilities-patched-in-redirection-for-contact-form-7-plugin/
- |
- | [!] Title: Redirection for Contact Form 7 < 2.3.4 - Authenticated Arbitrary Plugin Installation
- | Fixed in: 2.3.4
- | References:
- | - https://wpscan.com/vulnerability/75f7690d-7f6b-48a8-a9d1-95578a657920
- | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-24279
- | - https://www.wordfence.com/blog/2021/04/severe-vulnerabilities-patched-in-redirection-for-contact-form-7-plugin/
- |
- | [!] Title: Redirection for Contact Form 7 < 2.3.4 - Authenticated PHP Object Injection
- | Fixed in: 2.3.4
- | References:
- | - https://wpscan.com/vulnerability/db4ba6b0-887e-4ec1-8935-ab21d369b329
- | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-24280
- | - https://www.wordfence.com/blog/2021/04/severe-vulnerabilities-patched-in-redirection-for-contact-form-7-plugin/
- |
- | [!] Title: Redirection for Contact Form 7 < 2.3.4 - Authenticated Arbitrary Post Deletion
- | Fixed in: 2.3.4
- | References:
- | - https://wpscan.com/vulnerability/daf12b85-f5ad-4261-ab39-be6840ad3cdc
- | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-24281
- | - https://www.wordfence.com/blog/2021/04/severe-vulnerabilities-patched-in-redirection-for-contact-form-7-plugin/
- |
- | [!] Title: Redirection for Contact Form 7 < 2.3.4 - Unprotected AJAX Actions
- | Fixed in: 2.3.4
- | References:
- | - https://wpscan.com/vulnerability/def87e69-bade-431b-b101-d463a26406e9
- | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-24282
- | - https://www.wordfence.com/blog/2021/04/severe-vulnerabilities-patched-in-redirection-for-contact-form-7-plugin/
- |
- | [!] Title: Unauthorised AJAX Calls via Freemius
- | Fixed in: 2.5.0
- | Reference: https://wpscan.com/vulnerability/6dae6dca-7474-4008-9fe5-4c62b9f12d0a
- |
- | [!] Title: Redirection for Contact Form 7 < 2.5.0 - Reflected Cross-Site Scripting
- | Fixed in: 2.5.0
- | References:
- | - https://wpscan.com/vulnerability/05700942-3143-4978-89eb-814ceff74867
- | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0250
- |
- | [!] Title: Redirection for Contact Form 7 < 2.6.0 - Unauthenticated Options Update to Stored XSS
- | Fixed in: 2.6.0
- | References:
- | - https://wpscan.com/vulnerability/f42b2c72-50dd-4b76-84ad-8322c1a6e051
- | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-36913
- |
- | [!] Title: Freemius SDK < 2.5.10 - Reflected Cross-Site Scripting
- | Fixed in: 2.9.0
- | References:
- | - https://wpscan.com/vulnerability/58ab5352-d783-431a-b0a5-382381cc13fd
- | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-33999
- |
- | [!] Title: Redirection for Contact Form 7 < 3.0.0 - Missing Authorization
- | Fixed in: 3.0.0
- | References:
- | - https://wpscan.com/vulnerability/74ebe3ab-3af5-4bde-a943-2c97667a400a
- | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39920
- | - https://www.wordfence.com/threat-intel/vulnerabilities/id/9cf17c08-25b7-450d-acd9-963a1f79e495
- |
- | The version could not be determined.
Advertisement
Add Comment
Please, Sign In to add comment