The WooCommerce WordPress plugin before 8.6 does not prevent users with at least the contributor role from leaking products they shouldn't have access to. (e.g. private, draft and trashed products)
We have discovered 312,858 live websites that are affected by CVE-2024-1310.
| Product | |
| Category | Ecommerce |
| Vulnerable Domains | 312,858 live websites (24% of WooCommerce install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 371 versions ( 75% of all versions) |
| 68,177 websites | |
| 24,259 websites | |
| 17,775 websites | |
| 17,449 websites | |
| 16,213 websites | |
| 14,154 websites | |
| 10,478 websites | |
| 10,367 websites | |
| 8,846 websites | |
| 8,041 websites |
| .com | 132,243 websites |
| .ru | 12,707 websites |
| .it | 11,892 websites |
| .de | 9,530 websites |
| .co.uk | 8,570 websites |
| .org | 7,467 websites |
| .nl | 7,328 websites |
| .fr | 6,550 websites |
| .pl | 6,019 websites |
| .net | 5,882 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ***.com | *,*** | ||
| ***********.com | *,*** | ||
| *****************.com | *,*** | ||
| *************.com | *,*** | ||
| **********.com | *,*** | ||
| *********.com | *,*** | ||
| ************.ie | *,*** | ||
| **********.com | *,*** | ||
| *********.com | **,*** | ||
| ***********.net | **,*** |
FAQ