CVE-2024-0679




The ColorMag theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the plugin_action_callback() function in all versions up to, and including, 3.1.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to install and activate arbitrary plugins.



We have discovered 17,520 live websites that are affected by CVE-2024-0679.

Contact us to get more info




Affected Software

Product  ColorMag
Category Wordpress Themes
Vulnerable Versions
  • from 0 through 3.1.2
Total Vulnerable Versions251
Vulnerable Domains17,520 live websites (63.50% of ColorMag install base)


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2024-0679 and the relative popularity of websites


Details

  • Published - Jan 20, 2024
  • Updated - Jan 20, 2024

Credits

  • Sean Murphy (finder)




Countries

United States4,263 websites



Germany1,622 websites
France1,412 websites
Italy910 websites
Poland908 websites
Russia898 websites
Brazil791 websites
GB545 websites
Turkey482 websites
Netherlands367 websites

TLDs

.com6,326 websites
.org1,110 websites
.de986 websites
.ru774 websites
.net709 websites
.pl680 websites
.it658 websites
.com.br623 websites
.fr603 websites
.nl304 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2024-0679 through included software libraries and plugins.



References


Websites affected by CVE-2024-0679

Top websites that are affected by CVE-2024-0679. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
******.ru Russia**,***
******.com United States**,***
*****.com United States**,***
********.com United States**,***
***.***.be Belgium**,***
********.net United States**,***
***.************.com United States**,***
****.***.br Brazil**,***
***.*************.com United States**,***
********.net United States***,***
See full domain list