The Page Builder Gutenberg Blocks WordPress plugin before 3.1.7 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
We have discovered 151,368 live websites that are affected by CVE-2024-2369.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 151,368 live websites (70% of GoDaddy CoBlocks install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 82 versions ( 89% of all versions) |
| 125,941 websites | |
| 4,892 websites | |
| 3,151 websites | |
| 2,816 websites | |
| 2,136 websites | |
| 1,252 websites | |
| 1,170 websites | |
| 1,142 websites | |
| 834 websites | |
| 663 websites |
| .com | 108,629 websites |
| .org | 11,752 websites |
| .net | 5,027 websites |
| .co.uk | 2,615 websites |
| .ca | 1,961 websites |
| .fr | 1,212 websites |
| .de | 920 websites |
| .nl | 775 websites |
| .com.au | 696 websites |
| .ch | 523 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *********.com | ** | ||
| **********.com | *** | ||
| ********.com | *,*** | ||
| *******.com | *,*** | ||
| ***********.com | *,*** | ||
| **********.com | *,*** | ||
| ****************.com | *,*** | ||
| *****************.org | *,*** | ||
| ****.********.com | *,*** | ||
| *************.com | **,*** |
FAQ