CVE-2024-1360




The Colibri WP theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.94. This is due to missing or incorrect nonce validation on the colibriwp_install_plugin() function. This makes it possible for unauthenticated attackers to install recommended plugins via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.



We have discovered 23 live websites that are affected by CVE-2024-1360.

Contact us to get more info




Affected Software

Product  Colibri WP
Category Wordpress Themes
Vulnerable Versions
  • from 0 through 1.0.94
Total Vulnerable Versions83
Vulnerable Domains23 live websites (0.23% of Colibri WP install base)


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2024-1360 and the relative popularity of websites


Details

  • Published - Feb 23, 2024
  • Updated - Feb 23, 2024

Credits

  • Lucio Sá (finder)




Countries

United States9 websites



Denmark2 websites
Spain2 websites
France2 websites
Belgium1 websites
Chile1 websites
GB1 websites
Italy1 websites
Japan1 websites
Netherlands1 websites

TLDs

.com11 websites
.dk2 websites
.co.uk1 websites
.es1 websites
.eu1 websites
.fr1 websites
.io1 websites
.it1 websites
.org1 websites
.se1 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2024-1360 through included software libraries and plugins.



References


Websites affected by CVE-2024-1360

Top websites that are affected by CVE-2024-1360. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
***********.com United States*,***,***
***.******.com Spain*,***,***
********.******.se Sweden*,***,***
**********.io United States**,***,***
****.*****.eu Belgium**,***,***
*********.**.uk GB**,***,***
*********.com United States**,***,***
**************.dk Denmark**,***,***
************.com France**,***,***
***.*********.com Turkey**,***,***
See full domain list