CVE-2024-1049

The Page Builder Gutenberg Blocks – CoBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Icon Widget's in all versions up to, and including, 3.1.6 due to insufficient input sanitization and output escaping on the link value. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.


We have discovered 277,582 live websites that are affected by CVE-2024-1049.

Test my site




Affected Software

Product  GoDaddy CoBlocks
Category Wordpress Plugins
Vulnerable Domains277,582 live websites (81.03% of GoDaddy CoBlocks install base)
Vulnerable Versions
  • from 0 through 3.1.6
Vulnerable Versions Count119 versions ( 92.97% of all versions)



Details

  • Published - Mar 23, 2024
  • Updated - Aug 1, 2024

Credits

  • Craig Smith (finder)

CVE-2024-1049 usage by Country

United States269,521 websites



Germany1,733 websites
GB1,287 websites
France445 websites
Netherlands421 websites
Japan403 websites
Switzerland302 websites
Canada265 websites
Italy253 websites
Australia236 websites

CVE-2024-1049 usage by TLD

.com203,679 websites
.org20,821 websites
.net9,636 websites
.co.uk4,194 websites
.ca3,061 websites
.fr1,710 websites
.de1,468 websites
.nl1,242 websites
.com.au1,170 websites
.ch847 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-1049

Top websites that are affected by CVE-2024-1049. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.com United States**
********.*********.com United States**
**********.com United States***
********.com United States*,***
*********.com United States*,***
*******.com United States*,***
***********.com United States*,***
**********.com United States*,***
********.org United States*,***
****************.com United States*,***
See full domain list

FAQ

A total of 277,582 websites have been identified as vulnerable to CVE-2024-1049, discovered through global website indexing conducted by WebTechSurvey.
GoDaddy CoBlocks is susceptible to CVE-2024-1049 vulnerability.
GoDaddy CoBlocks versions before, and including, 3.1.6 are vulnerable to CVE-2024-1049.