The Popup Box – Create Countdown, Coupon, Video, Contact Form Popups plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the deactivate_plugin_option() function in all versions up to, and including, 4.9.7. This makes it possible for unauthenticated attackers to update the 'ays_pb_upgrade_plugin' option with arbitrary data.
We have discovered 6,317 live websites that are affected by CVE-2024-10861.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 6,317 live websites (43.98% of Ays Popup Box install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 304 versions ( 83.52% of all versions) |
![]() | 1,881 websites |
![]() | 704 websites |
![]() | 367 websites |
![]() | 255 websites |
![]() | 248 websites |
![]() | 213 websites |
![]() | 188 websites |
![]() | 168 websites |
![]() | 158 websites |
![]() | 151 websites |
.com | 2,168 websites |
.org | 340 websites |
.de | 314 websites |
.com.br | 230 websites |
.it | 227 websites |
.pl | 204 websites |
.nl | 170 websites |
.co.uk | 140 websites |
.fr | 130 websites |
.ru | 126 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
************.fr | ![]() | **,*** | |
*******.gr | ![]() | ***,*** | |
***********************.it | ![]() | ***,*** | |
********.com | ![]() | ***,*** | |
******.com | ![]() | ***,*** | |
************.com | ![]() | ***,*** | |
******.info | ![]() | ***,*** | |
******.nl | ![]() | ***,*** | |
***.***.br | ![]() | ***,*** | |
******.com | ![]() | ***,*** |
FAQ