CVE-2022-4384


Stream < 3.9.2 - Subscriber+ Alert Creation

The Stream WordPress plugin before 3.9.2 does not prevent users with little privileges on the site (like subscribers) from using its alert creation functionality, which may enable them to leak sensitive information.



We have discovered 6,159 live websites that are affected by CVE-2022-4384.

Contact us to get more info




Affected Software

Product  Stream
Category Wordpress Plugins
Vulnerable Versions
  • from 0 before 3.9.2
Total Vulnerable Versions40
Vulnerable Domains6,159 live websites (14.32% of Stream install base)


Common Weakness Enumeration


CWE-862 Missing Authorization


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2022-4384 and the relative popularity of websites


Details

  • Published - Feb 6, 2023

Credits

  • Krzysztof Zając (finder)
  • WPScan (coordinator)





Countries

United States3,302 websites



Australia384 websites
GB377 websites
Canada302 websites
Italy245 websites
Germany177 websites
Netherlands156 websites
Spain141 websites
Russia135 websites
France70 websites

TLDs

.com3,427 websites
.org325 websites
.com.au300 websites
.co.uk215 websites
.it199 websites
.ca158 websites
.net146 websites
.nl129 websites
.de117 websites
.ru108 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2022-4384 through included software libraries and plugins.



References


Websites affected by CVE-2022-4384

Top websites that are affected by CVE-2022-4384. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
*****.*********.org United States***
***.******.com United States*,***
***.**************.org United States**,***
***.*******.com United States**,***
***.*****.com United States**,***
***.******.com United States**,***
***.***********.com United States**,***
*****.edu United States**,***
***.*********.com United States**,***
***.************.com United States**,***
See full domain list