The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.10.29. This is due to missing or incorrect nonce validation on the register_reference() function. This makes it possible for unauthenticated attackers to update the connected API keys via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
We have discovered 16,708 live websites that are affected by CVE-2024-1162.
Product | ![]() |
Category | Wordpress Plugins |
Vulnerable Domains | 16,708 live websites (77.10% of OrbitFox install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 128 versions ( 81.53% of all versions) |
![]() | 4,204 websites |
![]() | 2,039 websites |
![]() | 1,698 websites |
![]() | 859 websites |
![]() | 627 websites |
![]() | 546 websites |
![]() | 517 websites |
![]() | 464 websites |
![]() | 451 websites |
![]() | 432 websites |
.com | 5,928 websites |
.de | 971 websites |
.org | 850 websites |
.fr | 730 websites |
.pl | 723 websites |
.nl | 635 websites |
.co.uk | 409 websites |
.it | 374 websites |
.net | 359 websites |
.ru | 343 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*****.com | ![]() | **,*** | |
*******.com | ![]() | **,*** | |
***************.org | ![]() | ***,*** | |
*****************.com | ![]() | ***,*** | |
*******.com | ![]() | ***,*** | |
*********.com | ![]() | ***,*** | |
**********************.org | ![]() | ***,*** | |
***********.fr | ![]() | ***,*** | |
***********.com | ![]() | ***,*** | |
*********.cz | ![]() | ***,*** |