CVE-2020-36753




The Hueman theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.6.3. This is due to missing or incorrect nonce validation on the save_meta_box() function. This makes it possible for unauthenticated attackers to save metabox data via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.



We have discovered 3,753 live websites that are affected by CVE-2020-36753.

Contact us to get more info




Affected Software

Product  Hueman
Category Wordpress Themes
Vulnerable Versions
  • from 0 through 3.6.3
Total Vulnerable Versions196
Vulnerable Domains3,753 live websites (22.66% of Hueman install base)



Details

  • Published - Oct 20, 2023
  • Updated - Oct 20, 2023

Credits

  • Jerome Bruandet (finder)




Countries

United States723 websites



Germany378 websites
Russia315 websites
Japan300 websites
France270 websites
Poland225 websites
Italy205 websites
Sweden134 websites
Netherlands94 websites
GB86 websites

TLDs

.com1,223 websites
.ru252 websites
.de219 websites
.org217 websites
.pl179 websites
.net166 websites
.it146 websites
.fr127 websites
.se118 websites
.nl74 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


References


Websites affected by CVE-2020-36753

Top websites that are affected by CVE-2020-36753. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.************************.**.uk GB**,***
***.********.org Germany**,***
************.com United States***,***
***.**************************.it Italy***,***
****************.com United States***,***
******.********.com Ukraine***,***
**********.com Hong Kong***,***
***.**********.gr Greece***,***
***.**********.com United States***,***
*********.ru Russia***,***
See full domain list