The WooCommerce WordPress plugin before 8.6 does not prevent users with at least the contributor role from leaking products they shouldn't have access to. (e.g. private, draft and trashed products)
We have discovered 536,829 live websites that are affected by CVE-2024-1310.
Product | ![]() |
Category | Ecommerce |
Vulnerable Domains | 536,829 live websites (35.85% of WooCommerce install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 425 versions ( 88.17% of all versions) |
![]() | 156,461 websites |
![]() | 53,218 websites |
![]() | 35,632 websites |
![]() | 22,478 websites |
![]() | 21,887 websites |
![]() | 16,448 websites |
![]() | 15,251 websites |
![]() | 14,517 websites |
![]() | 14,282 websites |
![]() | 13,420 websites |
.com | 235,005 websites |
.ru | 18,232 websites |
.de | 15,509 websites |
.co.uk | 15,308 websites |
.org | 13,352 websites |
.nl | 13,251 websites |
.it | 12,180 websites |
.fr | 10,896 websites |
.pl | 10,785 websites |
.com.au | 10,534 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
***.com | ![]() | *,*** | |
***********.com | ![]() | *,*** | |
*****************.com | ![]() | *,*** | |
*************.com | ![]() | *,*** | |
**********.com | ![]() | *,*** | |
**********.com | ![]() | *,*** | |
*********.com | ![]() | *,*** | |
************.ie | ![]() | *,*** | |
*********.com | ![]() | *,*** | |
**********.com | ![]() | *,*** |
FAQ