CVE-2024-11733

WordPress Popular Posts <= 7.1.0 - Unauthenticated Arbitrary Shortcode Execution

The The WordPress Popular Posts plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 7.1.0. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.


We have discovered 54,943 live websites that are affected by CVE-2024-11733.

Test my site




Affected Software

Product  WordPress Popular Posts
Category Wordpress Plugins
Vulnerable Domains54,943 live websites (61.05% of WordPress Popular Posts install base)
Vulnerable Versions
  • from 0 through 7.1
Vulnerable Versions Count109 versions ( 85.16% of all versions)


Common Weakness Enumeration

CWE-94 Improper Control of Generation of Code ('Code Injection')



Details

  • Published - Jan 3, 2025
  • Updated - Jan 6, 2025

Credits

  • Michael Mazzolini (finder)

CVE-2024-11733 usage by Country

United States12,758 websites



Japan24,323 websites
Germany2,736 websites
Russia1,705 websites
France1,696 websites
Poland1,098 websites
GB704 websites
Brazil558 websites
Vietnam549 websites

CVE-2024-11733 usage by TLD

.com28,501 websites
.net4,033 websites
.jp3,884 websites
.ru1,738 websites
.org1,614 websites
.co.jp1,176 websites
.de1,105 websites
.info986 websites
.pl851 websites
.com.br745 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-11733

Top websites that are affected by CVE-2024-11733. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***************.net United States***
************.com United States*,***
**************.de Germany*,***
*************.uk United States*,***
*******.***.in India*,***
*********.com United States*,***
**********.com United States*,***
**********.com United States**,***
***************.com United States**,***
*******************.com Japan**,***
See full domain list

FAQ

CVE-2024-11733 is Improper Control of Generation of Code ('Code Injection') in WordPress Popular Posts
A total of 54,943 websites have been identified as vulnerable to CVE-2024-11733, discovered through global website indexing conducted by WebTechSurvey.
WordPress Popular Posts is susceptible to CVE-2024-11733 vulnerability.
WordPress Popular Posts versions before, and including, 7.1 are vulnerable to CVE-2024-11733.