The The WordPress Popular Posts plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 7.1.0. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
We have discovered 54,943 live websites that are affected by CVE-2024-11733.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 54,943 live websites (61.05% of WordPress Popular Posts install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 109 versions ( 85.16% of all versions) |
![]() | 12,758 websites |
![]() | 24,323 websites |
![]() | 2,736 websites |
![]() | 1,705 websites |
![]() | 1,696 websites |
![]() | 1,098 websites |
![]() | 704 websites |
![]() | 558 websites |
![]() | 549 websites |
.com | 28,501 websites |
.net | 4,033 websites |
.jp | 3,884 websites |
.ru | 1,738 websites |
.org | 1,614 websites |
.co.jp | 1,176 websites |
.de | 1,105 websites |
.info | 986 websites |
.pl | 851 websites |
.com.br | 745 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
***************.net | ![]() | *** | |
************.com | ![]() | *,*** | |
**************.de | ![]() | *,*** | |
*************.uk | ![]() | *,*** | |
*******.***.in | ![]() | *,*** | |
*********.com | ![]() | *,*** | |
**********.com | ![]() | *,*** | |
**********.com | ![]() | **,*** | |
***************.com | ![]() | **,*** | |
*******************.com | ![]() | **,*** |
FAQ