CVE-2024-0590




The Microsoft Clarity plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.9.3. This is due to missing nonce validation on the edit_clarity_project_id() function. This makes it possible for unauthenticated attackers to change the project id and add malicious JavaScript via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.



We have discovered 133 live websites that are affected by CVE-2024-0590.

Contact us to get more info




Affected Software

Product  Microsoft Clarity
Category Analytics
Vulnerable Versions
  • from 0 through 0.9.3
Total Vulnerable Versions24
Vulnerable Domains133 live websites (100.00% of Microsoft Clarity install base)


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2024-0590 and the relative popularity of websites


Details

  • Published - Feb 20, 2024
  • Updated - Feb 20, 2024

Credits

  • Kodai Kubono (finder)




Countries

United States55 websites



GB11 websites
Japan7 websites
Switzerland5 websites
China5 websites
India5 websites
Canada4 websites
France4 websites
Australia3 websites
Brazil3 websites

TLDs

.com77 websites
.ch5 websites
.pl3 websites
.de3 websites
.co.jp2 websites
.se2 websites
.com.au2 websites
.com.br2 websites
.ru2 websites
.nl2 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2024-0590 through included software libraries and plugins.



References


Websites affected by CVE-2024-0590

Top websites that are affected by CVE-2024-0590. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
***.****.pl Poland**,***
***.******.com United States***,***
******.london GB***,***
****.***.**.kr Korea, South***,***
***.*****.se Singapore***,***
***.******************.pl Poland***,***
***.*******.com France***,***
******************.com United States***,***
*********.******.com United States***,***
***.*****.com GB***,***
See full domain list