CVE-2024-0612

The Content Views – Post Grid, Slider, Accordion (Gutenberg Blocks and Shortcode) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.


We have discovered 4,943 live websites that are affected by CVE-2024-0612.

Run a Free Instant Scan




Affected Software

Product  Content Views
Category Wordpress Plugins
Vulnerable Domains4,943 live websites (12% of Content Views install base)
Vulnerable Versions
  • from 0 through 3.6.2
Vulnerable Versions Count69 versions ( 84% of all versions)



Details

  • Published - Feb 5, 2024
  • Updated - Aug 1, 2024

Credits

  • Akbar Kustirama (finder)

Website Distribution by Country

Number of websites using CVE-2024-0612
United States1,137 websites



Russia551 websites
Germany325 websites
Italy278 websites
France247 websites
Japan222 websites
GB159 websites
Canada152 websites
Netherlands123 websites
Spain122 websites

Website Distribution by TLD

Number of websites using CVE-2024-0612
.com1,784 websites
.ru453 websites
.org337 websites
.it188 websites
.de148 websites
.net144 websites
.nl107 websites
.co.uk94 websites
.fr82 websites
.pl77 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-0612

Top websites that are affected by CVE-2024-0612. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.app Bulgaria**,***
**********.com United States**,***
****.***.gr Greece***,***
**********.com United States***,***
*******.***.za South Africa***,***
*******.******.ru Russia***,***
***********.com United States***,***
****************.org United States***,***
*********.com United States***,***
******.fr France***,***
See full domain list

FAQ

A total of 4,943 websites have been identified as vulnerable to CVE-2024-0612, based on global website indexing conducted by WebTechSurvey.
The Content Views is affected by the CVE-2024-0612 vulnerability.
Content Views versions up to and including 3.6.2 are vulnerable to CVE-2024-0612.