CVE-2024-2484

Orbit Fox by ThemeIsle <= 2.10.34 - Authenticated (Contributor+) Stored Cross-Site Scripting via Services and Post Type Grid Widgets

The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Services and Post Type Grid widgets in all versions up to, and including, 2.10.34 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.


We have discovered 16,888 live websites that are affected by CVE-2024-2484.

Test my site




Affected Software

Product  OrbitFox
Category Wordpress Plugins
Vulnerable Domains16,888 live websites (77.93% of OrbitFox install base)
Vulnerable Versions
  • from 0 through 2.10.34
Vulnerable Versions Count133 versions ( 84.71% of all versions)



Details

  • Published - Jun 22, 2024
  • Updated - Aug 1, 2024

Credits

  • wesley (finder)

CVE-2024-2484 usage by Country

United States4,235 websites



Germany2,060 websites
France1,721 websites
Poland866 websites
Netherlands631 websites
GB552 websites
Japan522 websites
Spain472 websites
Italy456 websites
Russia438 websites

CVE-2024-2484 usage by TLD

.com5,982 websites
.de982 websites
.org859 websites
.fr737 websites
.pl726 websites
.nl640 websites
.co.uk411 websites
.it383 websites
.net364 websites
.ru349 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-2484

Top websites that are affected by CVE-2024-2484. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.com Korea, South**,***
*******.com Germany**,***
***************.org United States***,***
*****************.com United States***,***
*******.com Cyprus***,***
*********.com Canada***,***
**********************.org United States***,***
***********.fr France***,***
***********.com Argentina***,***
*********.cz Czech Republic***,***
See full domain list

FAQ

A total of 16,888 websites have been identified as vulnerable to CVE-2024-2484, discovered through global website indexing conducted by WebTechSurvey.
OrbitFox is susceptible to CVE-2024-2484 vulnerability.
OrbitFox versions before, and including, 2.10.34 are vulnerable to CVE-2024-2484.