CVE-2024-0897

The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image URL parameter in all versions up to, and including, 2.7.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.


We have discovered 50,984 live websites that are affected by CVE-2024-0897.

Test my site




Affected Software

Product  Beaver Builder
Category Wordpress Plugins
Vulnerable Domains50,984 live websites (34.43% of Beaver Builder install base)
Vulnerable Versions
  • from 0 through 2.7.4.2
Vulnerable Versions Count289 versions ( 88.65% of all versions)



Details

  • Published - Mar 13, 2024
  • Updated - Aug 1, 2024

Credits

  • Maxuel (finder)

CVE-2024-0897 usage by Country

United States35,813 websites



Germany2,095 websites
GB1,785 websites
Japan1,635 websites
France1,211 websites
Singapore987 websites
Australia815 websites
China780 websites
Netherlands744 websites
Canada499 websites

CVE-2024-0897 usage by TLD

.com34,784 websites
.org2,755 websites
.co.uk1,419 websites
.net1,283 websites
.com.au1,167 websites
.de1,138 websites
.ca888 websites
.nl775 websites
.jp461 websites
.fr366 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-0897

Top websites that are affected by CVE-2024-0897. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**************.com United States**,***
****.ca United States**,***
****.net United States**,***
**********.com United States**,***
**********.com United States**,***
**********.com United States**,***
************.com United States**,***
*********.com United States**,***
********.com United States***,***
*****.com United States***,***
See full domain list

FAQ

A total of 50,984 websites have been identified as vulnerable to CVE-2024-0897, discovered through global website indexing conducted by WebTechSurvey.
Beaver Builder is susceptible to CVE-2024-0897 vulnerability.
Beaver Builder versions before, and including, 2.7.4.2 are vulnerable to CVE-2024-0897.