CVE-2024-25910


WordPress MoveTo Plugin <= 6.2 is vulnerable to SQL Injection

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Skymoonlabs MoveTo.This issue affects MoveTo: from n/a through 6.2.



We have discovered 49 live websites that are affected by CVE-2024-25910.

Contact us to get more info




Affected Software

Product  MoveTo
Category Animation
Vulnerable Versions
  • from 0 through 6.2
Total Vulnerable Versions10
Vulnerable Domains49 live websites (100.00% of MoveTo install base)


Common Weakness Enumeration


CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')



Details

  • Published - Feb 28, 2024
  • Updated - Feb 28, 2024

Credits

  • Dave Jong (Patchstack) (finder)





Countries

United States17 websites



Japan17 websites
Netherlands5 websites
Australia2 websites
Russia2 websites
Brazil1 websites
China1 websites
Greenland1 websites
Greece1 websites
New Zealand1 websites

TLDs

.com21 websites
.jp7 websites
.nl5 websites
.org5 websites
.co.jp1 websites
.com.au1 websites
.eu1 websites
.pl1 websites
.ru1 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


References


Websites affected by CVE-2024-25910

Top websites that are affected by CVE-2024-25910. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***********.jp Japan***,***
**********.**.jp Japan*,***,***
*************.com Japan*,***,***
***.******.jp Japan*,***,***
****************.com United States*,***,***
***************.org United States*,***,***
******************.jp Japan*,***,***
********.com United States*,***,***
*****************.com United States*,***,***
*********.com United States*,***,***
See full domain list