The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image URL parameter in all versions up to, and including, 2.7.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 50,984 live websites that are affected by CVE-2024-0897.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 50,984 live websites (34.43% of Beaver Builder install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 289 versions ( 88.65% of all versions) |
![]() | 35,813 websites |
![]() | 2,095 websites |
![]() | 1,785 websites |
![]() | 1,635 websites |
![]() | 1,211 websites |
![]() | 987 websites |
![]() | 815 websites |
![]() | 780 websites |
![]() | 744 websites |
![]() | 499 websites |
.com | 34,784 websites |
.org | 2,755 websites |
.co.uk | 1,419 websites |
.net | 1,283 websites |
.com.au | 1,167 websites |
.de | 1,138 websites |
.ca | 888 websites |
.nl | 775 websites |
.jp | 461 websites |
.fr | 366 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
**************.com | ![]() | **,*** | |
****.ca | ![]() | **,*** | |
****.net | ![]() | **,*** | |
**********.com | ![]() | **,*** | |
**********.com | ![]() | **,*** | |
**********.com | ![]() | **,*** | |
************.com | ![]() | **,*** | |
*********.com | ![]() | **,*** | |
********.com | ![]() | ***,*** | |
*****.com | ![]() | ***,*** |
FAQ