CVE-2024-1499

The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Pricing Table widget in the $settings['title_tags'] parameter in all versions up to, and including, 2.10.30 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.


We have discovered 16,763 live websites that are affected by CVE-2024-1499.

Test my site




Affected Software

Product  OrbitFox
Category Wordpress Plugins
Vulnerable Domains16,763 live websites (77.35% of OrbitFox install base)
Vulnerable Versions
  • from 0 through 2.10.30
Vulnerable Versions Count129 versions ( 82.17% of all versions)



Details

  • Published - Mar 13, 2024
  • Updated - Aug 1, 2024

Credits

  • Maxuel (finder)

CVE-2024-1499 usage by Country

United States4,214 websites



Germany2,047 websites
France1,707 websites
Poland860 websites
Netherlands628 websites
GB549 websites
Japan520 websites
Spain466 websites
Italy453 websites
Russia435 websites

CVE-2024-1499 usage by TLD

.com5,946 websites
.de975 websites
.org854 websites
.fr732 websites
.pl724 websites
.nl637 websites
.co.uk411 websites
.it379 websites
.net360 websites
.ru346 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-1499

Top websites that are affected by CVE-2024-1499. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.com Korea, South**,***
*******.com Germany**,***
***************.org United States***,***
*****************.com United States***,***
*******.com Cyprus***,***
*********.com Canada***,***
**********************.org United States***,***
***********.fr France***,***
***********.com Argentina***,***
*********.cz Czech Republic***,***
See full domain list

FAQ

A total of 16,763 websites have been identified as vulnerable to CVE-2024-1499, discovered through global website indexing conducted by WebTechSurvey.
OrbitFox is susceptible to CVE-2024-1499 vulnerability.
OrbitFox versions before, and including, 2.10.30 are vulnerable to CVE-2024-1499.