The WPBakery Page Builder Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'per_line_mobile' shortcode in all versions up to, and including, 3.8.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 2,262 live websites that are affected by CVE-2024-2079.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 2,262 live websites (100% of Addons For Visual Composer install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 0 versions ( less than 0.1% of all versions) |
| 459 websites | |
| 214 websites | |
| 204 websites | |
| 156 websites | |
| 122 websites | |
| 84 websites | |
| 82 websites | |
| 58 websites | |
| 47 websites | |
| 45 websites |
| .com | 878 websites |
| .it | 134 websites |
| .org | 121 websites |
| .de | 92 websites |
| .ru | 92 websites |
| .net | 55 websites |
| .fr | 51 websites |
| .com.br | 45 websites |
| .pl | 42 websites |
| .co.uk | 36 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ******.org | ***,*** | ||
| *******.org | ***,*** | ||
| *****************.com | ***,*** | ||
| ***********.com | ***,*** | ||
| *************.net | ***,*** | ||
| *****************.org | ***,*** | ||
| ***********.org | ***,*** | ||
| *****.ca | ***,*** | ||
| ***********.***.uk | ***,*** | ||
| *************.org | ***,*** |
FAQ