The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the code editor in all versions up to, and including, 1.58.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 34,105 live websites that are affected by CVE-2024-0961.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 34,105 live websites (39.62% of So Widgets Bundle install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 178 versions ( 78.07% of all versions) |
![]() | 7,703 websites |
![]() | 4,618 websites |
![]() | 2,518 websites |
![]() | 1,841 websites |
![]() | 1,580 websites |
![]() | 1,453 websites |
![]() | 1,415 websites |
![]() | 1,314 websites |
![]() | 982 websites |
![]() | 833 websites |
.com | 12,085 websites |
.de | 2,516 websites |
.nl | 1,432 websites |
.org | 1,366 websites |
.co.uk | 1,173 websites |
.pl | 1,129 websites |
.ru | 1,068 websites |
.fr | 983 websites |
.it | 764 websites |
.net | 728 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
****.***.tr | ![]() | **,*** | |
*************.com | ![]() | **,*** | |
*****************.com | ![]() | **,*** | |
***********.com | ![]() | **,*** | |
*********.org | ![]() | **,*** | |
******.org | ![]() | **,*** | |
*********.com | ![]() | **,*** | |
****.**.th | ![]() | **,*** | |
***.it | ![]() | **,*** | |
***.org | ![]() | **,*** |
FAQ