CVE-2024-1894

The Burst Statistics – Privacy-Friendly Analytics for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'burst_total_pageviews_count' custom meta field in all versions up to, and including, 1.5.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Note that this exploit only functions if the victim has the 'Show Toolbar when viewing site' option enabled in their profile.


We have discovered 7,175 live websites that are affected by CVE-2024-1894.

Test my site




Affected Software

Product  Burst Statistics
Category Wordpress Plugins
Vulnerable Domains7,175 live websites (9.17% of Burst Statistics install base)
Vulnerable Versions
  • from 0 through 1.5.6.1
Vulnerable Versions Count35 versions ( 79.55% of all versions)



Details

  • Published - Mar 13, 2024
  • Updated - Aug 1, 2024

Credits

  • Craig Smith (finder)

CVE-2024-1894 usage by Country

United States1,771 websites



Germany1,274 websites
France644 websites
Netherlands372 websites
GB306 websites
Denmark234 websites
Spain202 websites
Italy199 websites
Brazil198 websites
Poland180 websites

CVE-2024-1894 usage by TLD

.com2,629 websites
.de715 websites
.nl378 websites
.fr276 websites
.com.br274 websites
.org271 websites
.co.uk194 websites
.it171 websites
.pl142 websites
.net138 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-1894

Top websites that are affected by CVE-2024-1894. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.de United States***,***
**********.net United States***,***
***********.com India***,***
******.org United States***,***
***************.com United States***,***
*********.fr France***,***
*********.com Netherlands***,***
***********.com Netherlands***,***
********.com United States***,***
***************.com South Africa***,***
See full domain list

FAQ

A total of 7,175 websites have been identified as vulnerable to CVE-2024-1894, discovered through global website indexing conducted by WebTechSurvey.
Burst Statistics is susceptible to CVE-2024-1894 vulnerability.
Burst Statistics versions before, and including, 1.5.6.1 are vulnerable to CVE-2024-1894.