CVE-2020-36755




The Customizr theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.3.0. This is due to missing or incorrect nonce validation on the czr_fn_post_fields_save() function. This makes it possible for unauthenticated attackers to post fields via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.



We have discovered 466 live websites that are affected by CVE-2020-36755.

Contact us to get more info




Affected Software

Product  Customizr
Category Wordpress Themes
Vulnerable Versions
  • from 0 through 4.3
Total Vulnerable Versions164
Vulnerable Domains466 live websites (18.34% of Customizr install base)


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2020-36755 and the relative popularity of websites


Details

  • Published - Oct 20, 2023
  • Updated - Oct 20, 2023

Credits

  • Jerome Bruandet (finder)




Countries

United States116 websites



Germany62 websites
France54 websites
Italy24 websites
Spain24 websites
GB21 websites
Netherlands16 websites
Japan15 websites
Poland15 websites
Canada12 websites

TLDs

.com171 websites
.org50 websites
.de39 websites
.eu18 websites
.fr16 websites
.it15 websites
.net13 websites
.nl12 websites
.pl10 websites
.co.uk10 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2020-36755 through included software libraries and plugins.



References


Websites affected by CVE-2020-36755

Top websites that are affected by CVE-2020-36755. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
*****.***.edu United States***,***
***********.com United States***,***
***.********.pl Poland***,***
***************.*********.com United States***,***
***.**************.com United States***,***
*******.com United States***,***
******.***.za South Africa***,***
*******.*****.ca Canada***,***
***.****.com United States***,***
***.*******.com France***,***
See full domain list