The WPForms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wpforms_is_admin_page' function in versions starting from 1.8.4 up to, and including, 1.9.2.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to refund payments and cancel subscriptions.
We have discovered 115,344 live websites that are affected by CVE-2024-11205.
Product | |
Category | Form Builders |
Vulnerable Domains | 115,344 live websites (20.93% of WPForms install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 40 versions ( 20.00% of all versions) |
![]() | 39,793 websites |
![]() | 15,342 websites |
![]() | 7,683 websites |
![]() | 5,770 websites |
![]() | 4,906 websites |
![]() | 3,690 websites |
![]() | 2,743 websites |
![]() | 2,511 websites |
![]() | 2,311 websites |
![]() | 1,912 websites |
.com | 50,836 websites |
.de | 5,782 websites |
.org | 5,383 websites |
.co.uk | 3,664 websites |
.fr | 3,237 websites |
.nl | 2,998 websites |
.it | 2,911 websites |
.net | 2,505 websites |
.com.br | 2,467 websites |
.com.au | 2,107 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
********.com | ![]() | *,*** | |
*******.com | ![]() | *,*** | |
******.com | ![]() | *,*** | |
***********************.com | ![]() | *,*** | |
*******.com | ![]() | *,*** | |
*******.org | ![]() | *,*** | |
*************.com | ![]() | *,*** | |
****.bg | ![]() | *,*** | |
****************.org | ![]() | **,*** | |
*********.com | ![]() | **,*** |
FAQ