CVE-2024-2079

The WPBakery Page Builder Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'per_line_mobile' shortcode in all versions up to, and including, 3.8.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.


We have discovered 2,262 live websites that are affected by CVE-2024-2079.

Run a Free Instant Scan




Affected Software

Product  Addons For Visual Composer
Category Wordpress Plugins
Vulnerable Domains2,262 live websites (100% of Addons For Visual Composer install base)
Vulnerable Versions
  • from 0 through 3.8.1
Vulnerable Versions Count0 versions ( less than 0.1% of all versions)



Details

  • Published - Mar 13, 2024
  • Updated - Aug 1, 2024

Credits

  • Krzysztof Zając (finder)

Website Distribution by Country

Number of websites using CVE-2024-2079
United States459 websites



Germany214 websites
Italy204 websites
France156 websites
Russia122 websites
GB84 websites
Spain82 websites
Poland58 websites
Brazil47 websites
India45 websites

Website Distribution by TLD

Number of websites using CVE-2024-2079
.com878 websites
.it134 websites
.org121 websites
.de92 websites
.ru92 websites
.net55 websites
.fr51 websites
.com.br45 websites
.pl42 websites
.co.uk36 websites

Websites affected by CVE-2024-2079

Top websites that are affected by CVE-2024-2079. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******.org United States***,***
*******.org United States***,***
*****************.com United States***,***
***********.com United States***,***
*************.net United States***,***
*****************.org United States***,***
***********.org France***,***
*****.ca Canada***,***
***********.***.uk GB***,***
*************.org Spain***,***
See full domain list

FAQ

A total of 2,262 websites have been identified as vulnerable to CVE-2024-2079, based on global website indexing conducted by WebTechSurvey.
The Addons For Visual Composer is affected by the CVE-2024-2079 vulnerability.
Addons For Visual Composer versions up to and including 3.8.1 are vulnerable to CVE-2024-2079.