The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘alt’ parameter in all versions up to, and including, 2.9.1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 360,154 live websites that are affected by CVE-2024-13377.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 360,154 live websites (64.73% of Gravity Forms install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 704 versions ( 98.32% of all versions) |
![]() | 241,240 websites |
![]() | 15,601 websites |
![]() | 14,516 websites |
![]() | 13,607 websites |
![]() | 12,909 websites |
![]() | 12,638 websites |
![]() | 6,518 websites |
![]() | 4,054 websites |
![]() | 3,373 websites |
![]() | 3,367 websites |
.com | 207,744 websites |
.org | 23,819 websites |
.com.au | 18,466 websites |
.nl | 17,092 websites |
.co.uk | 14,426 websites |
.ca | 9,050 websites |
.net | 7,673 websites |
.fr | 6,834 websites |
.de | 5,290 websites |
.be | 2,859 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
******.org | ![]() | *** | |
*********.de | ![]() | *** | |
*********.com | ![]() | *** | |
***********.com | ![]() | *,*** | |
**********.com | ![]() | *,*** | |
************.com | ![]() | *,*** | |
***.com | ![]() | *,*** | |
*******.com | ![]() | *,*** | |
**********.com | ![]() | *,*** | |
***********.com | ![]() | *,*** |
FAQ