CVE-2024-10861

Popup Box – Create Countdown, Coupon, Video, Contact Form Popups <= 4.9.7 - Missing Authorization to Unauthenticated Limited Options Update

The Popup Box – Create Countdown, Coupon, Video, Contact Form Popups plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the deactivate_plugin_option() function in all versions up to, and including, 4.9.7. This makes it possible for unauthenticated attackers to update the 'ays_pb_upgrade_plugin' option with arbitrary data.


We have discovered 6,317 live websites that are affected by CVE-2024-10861.

Test my site




Affected Software

Product  Ays Popup Box
Category Wordpress Plugins
Vulnerable Domains6,317 live websites (43.98% of Ays Popup Box install base)
Vulnerable Versions
  • from 0 through 4.9.7
Vulnerable Versions Count304 versions ( 83.52% of all versions)


Common Weakness Enumeration

CWE-862 Missing Authorization



Details

  • Published - Nov 16, 2024
  • Updated - Nov 19, 2024

Credits

  • Trương Hữu Phúc (truonghuuphuc) (finder)

CVE-2024-10861 usage by Country

United States1,881 websites



Germany704 websites
France367 websites
Poland255 websites
Italy248 websites
GB213 websites
Brazil188 websites
Cyprus168 websites
Netherlands158 websites
Russia151 websites

CVE-2024-10861 usage by TLD

.com2,168 websites
.org340 websites
.de314 websites
.com.br230 websites
.it227 websites
.pl204 websites
.nl170 websites
.co.uk140 websites
.fr130 websites
.ru126 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-10861

Top websites that are affected by CVE-2024-10861. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
************.fr France**,***
*******.gr Greece***,***
***********************.it Italy***,***
********.com United States***,***
******.com United States***,***
************.com France***,***
******.info United States***,***
******.nl Netherlands***,***
***.***.br Brazil***,***
******.com United States***,***
See full domain list

FAQ

CVE-2024-10861 is Missing Authorization in Ays Popup Box
A total of 6,317 websites have been identified as vulnerable to CVE-2024-10861, discovered through global website indexing conducted by WebTechSurvey.
Ays Popup Box is susceptible to CVE-2024-10861 vulnerability.
Ays Popup Box versions before, and including, 4.9.7 are vulnerable to CVE-2024-10861.