CVE-2024-1120

The NextMove Lite – Thank You Page for WooCommerce and Finale Lite – Sales Countdown Timer & Discount for WooCommerce plugins for WordPress are vulnerable to unauthorized access of data due to a missing capability check on the download_tools_settings() function in all versions up to, and including, 2.17.0. This makes it possible for unauthenticated attackers to export system information that can aid attackers in an attack.


We have discovered 243 live websites that are affected by CVE-2024-1120.

Run a Free Instant Scan




Affected Software

Product  Finale Woocommerce Sales Countdown Timer Discount
Category Wordpress Plugins
Vulnerable Domains243 live websites (20% of Finale Woocommerce Sales Countdown Timer Discount install base)
Vulnerable Versions
  • from 0 through 2.18
Vulnerable Versions Count12 versions ( 75% of all versions)



Details

  • Published - Mar 1, 2024
  • Updated - Aug 28, 2024

Credits

  • Francesco Carlucci (finder)

Website Distribution by Country

Number of websites using CVE-2024-1120
United States58 websites



Germany20 websites
Italy14 websites
Spain10 websites
GB10 websites
Russia10 websites
India8 websites
France8 websites
Poland8 websites
Ukraine7 websites

Website Distribution by TLD

Number of websites using CVE-2024-1120
.com111 websites
.ru8 websites
.es8 websites
.pl8 websites
.it6 websites
.nl5 websites
.co.uk4 websites
.org4 websites
.co3 websites
.com.au3 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-1120

Top websites that are affected by CVE-2024-1120. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*************.com United States***,***
*******.com United States***,***
**********.com United States*,***,***
****.tw Taiwan*,***,***
***.***.au Australia*,***,***
***************.ir Iran*,***,***
*********.pl Poland*,***,***
**********.vn Vietnam*,***,***
**********.com Hong Kong*,***,***
******.ru Russia*,***,***
See full domain list

FAQ

A total of 243 websites have been identified as vulnerable to CVE-2024-1120, based on global website indexing conducted by WebTechSurvey.
The Finale Woocommerce Sales Countdown Timer Discount is affected by the CVE-2024-1120 vulnerability.
Finale Woocommerce Sales Countdown Timer Discount versions up to and including 2.18 are vulnerable to CVE-2024-1120.