CVE-2024-1070

The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the features attribute in all versions up to, and including, 1.58.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.


We have discovered 34,442 live websites that are affected by CVE-2024-1070.

Test my site




Affected Software

Product  So Widgets Bundle
Category Wordpress Plugins
Vulnerable Domains34,442 live websites (40.01% of So Widgets Bundle install base)
Vulnerable Versions
  • from 0 through 1.58.2
Vulnerable Versions Count179 versions ( 78.51% of all versions)



Details

  • Published - Feb 20, 2024
  • Updated - Aug 1, 2024

Credits

  • Mdr001 (finder)

CVE-2024-1070 usage by Country

United States7,783 websites



Germany4,669 websites
France2,539 websites
Japan1,851 websites
GB1,594 websites
Netherlands1,468 websites
Poland1,419 websites
Russia1,325 websites
Italy993 websites
Spain842 websites

CVE-2024-1070 usage by TLD

.com12,207 websites
.de2,553 websites
.nl1,443 websites
.org1,380 websites
.co.uk1,180 websites
.pl1,133 websites
.ru1,076 websites
.fr990 websites
.it772 websites
.net734 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-1070

Top websites that are affected by CVE-2024-1070. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.***.tr Turkey**,***
*************.com United States**,***
*****************.com United States**,***
***********.com United States**,***
*********.org United States**,***
******.org United States**,***
*********.com Indonesia**,***
****.**.th Thailand**,***
***.it France**,***
***.org United States**,***
See full domain list

FAQ

A total of 34,442 websites have been identified as vulnerable to CVE-2024-1070, discovered through global website indexing conducted by WebTechSurvey.
So Widgets Bundle is susceptible to CVE-2024-1070 vulnerability.
So Widgets Bundle versions before, and including, 1.58.2 are vulnerable to CVE-2024-1070.