CVE-2024-0961

The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the code editor in all versions up to, and including, 1.58.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.


We have discovered 34,105 live websites that are affected by CVE-2024-0961.

Test my site




Affected Software

Product  So Widgets Bundle
Category Wordpress Plugins
Vulnerable Domains34,105 live websites (39.62% of So Widgets Bundle install base)
Vulnerable Versions
  • from 0 through 1.58.1
Vulnerable Versions Count178 versions ( 78.07% of all versions)



Details

  • Published - Feb 5, 2024
  • Updated - Aug 1, 2024

Credits

  • Craig Smith (finder)

CVE-2024-0961 usage by Country

United States7,703 websites



Germany4,618 websites
France2,518 websites
Japan1,841 websites
GB1,580 websites
Netherlands1,453 websites
Poland1,415 websites
Russia1,314 websites
Italy982 websites
Spain833 websites

CVE-2024-0961 usage by TLD

.com12,085 websites
.de2,516 websites
.nl1,432 websites
.org1,366 websites
.co.uk1,173 websites
.pl1,129 websites
.ru1,068 websites
.fr983 websites
.it764 websites
.net728 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-0961

Top websites that are affected by CVE-2024-0961. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.***.tr Turkey**,***
*************.com United States**,***
*****************.com United States**,***
***********.com United States**,***
*********.org United States**,***
******.org United States**,***
*********.com Indonesia**,***
****.**.th Thailand**,***
***.it France**,***
***.org United States**,***
See full domain list

FAQ

A total of 34,105 websites have been identified as vulnerable to CVE-2024-0961, discovered through global website indexing conducted by WebTechSurvey.
So Widgets Bundle is susceptible to CVE-2024-0961 vulnerability.
So Widgets Bundle versions before, and including, 1.58.1 are vulnerable to CVE-2024-0961.