The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the features attribute in all versions up to, and including, 1.58.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 34,442 live websites that are affected by CVE-2024-1070.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 34,442 live websites (40.01% of So Widgets Bundle install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 179 versions ( 78.51% of all versions) |
![]() | 7,783 websites |
![]() | 4,669 websites |
![]() | 2,539 websites |
![]() | 1,851 websites |
![]() | 1,594 websites |
![]() | 1,468 websites |
![]() | 1,419 websites |
![]() | 1,325 websites |
![]() | 993 websites |
![]() | 842 websites |
.com | 12,207 websites |
.de | 2,553 websites |
.nl | 1,443 websites |
.org | 1,380 websites |
.co.uk | 1,180 websites |
.pl | 1,133 websites |
.ru | 1,076 websites |
.fr | 990 websites |
.it | 772 websites |
.net | 734 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
****.***.tr | ![]() | **,*** | |
*************.com | ![]() | **,*** | |
*****************.com | ![]() | **,*** | |
***********.com | ![]() | **,*** | |
*********.org | ![]() | **,*** | |
******.org | ![]() | **,*** | |
*********.com | ![]() | **,*** | |
****.**.th | ![]() | **,*** | |
***.it | ![]() | **,*** | |
***.org | ![]() | **,*** |
FAQ