The Content Views – Post Grid, Slider, Accordion (Gutenberg Blocks and Shortcode) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
We have discovered 4,943 live websites that are affected by CVE-2024-0612.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 4,943 live websites (12% of Content Views install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 69 versions ( 84% of all versions) |
| 1,137 websites | |
| 551 websites | |
| 325 websites | |
| 278 websites | |
| 247 websites | |
| 222 websites | |
| 159 websites | |
| 152 websites | |
| 123 websites | |
| 122 websites |
| .com | 1,784 websites |
| .ru | 453 websites |
| .org | 337 websites |
| .it | 188 websites |
| .de | 148 websites |
| .net | 144 websites |
| .nl | 107 websites |
| .co.uk | 94 websites |
| .fr | 82 websites |
| .pl | 77 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *****.app | **,*** | ||
| **********.com | **,*** | ||
| ****.***.gr | ***,*** | ||
| **********.com | ***,*** | ||
| *******.***.za | ***,*** | ||
| *******.******.ru | ***,*** | ||
| ***********.com | ***,*** | ||
| ****************.org | ***,*** | ||
| *********.com | ***,*** | ||
| ******.fr | ***,*** |
FAQ