CVE-2024-30421

WordPress Events Manager plugin <= 6.4.7.1 - Cross Site Request Forgery (CSRF) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in Pixelite Events Manager.This issue affects Events Manager: from n/a through 6.4.7.1.


We have discovered 11,858 live websites that are affected by CVE-2024-30421.

Test my site




Affected Software

Product  Events Manager for WordPress
Category Wordpress Plugins
Vulnerable Domains11,858 live websites (30.88% of Events Manager for WordPress install base)
Vulnerable Versions
  • from 0 through 6.4.7.1
Vulnerable Versions Count83 versions ( 71.55% of all versions)


Common Weakness Enumeration

CWE-352 Cross-Site Request Forgery (CSRF)



Details

  • Published - Mar 28, 2024
  • Updated - Aug 2, 2024

Credits

  • Dhabaleshwar Das (Patchstack Alliance) (finder)

CVE-2024-30421 usage by Country

United States3,437 websites



Germany2,211 websites
France1,096 websites
GB464 websites
Netherlands462 websites
Italy395 websites
Japan377 websites
Switzerland279 websites
Spain264 websites
Poland193 websites

CVE-2024-30421 usage by TLD

.com3,395 websites
.de1,438 websites
.org1,434 websites
.fr503 websites
.nl441 websites
.it332 websites
.co.uk260 websites
.net249 websites
.ch239 websites
.at200 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-30421

Top websites that are affected by CVE-2024-30421. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.*******.**********.it Italy**,***
*********.*******.org United States**,***
******.***.uk United States**,***
*******.org United States**,***
********.org United States**,***
*****.***.edu United States**,***
****.**.in United States**,***
********************.com United States**,***
*************.cat Spain***,***
**************.it Italy***,***
See full domain list

FAQ

CVE-2024-30421 is Cross-Site Request Forgery (CSRF) in Events Manager for WordPress
A total of 11,858 websites have been identified as vulnerable to CVE-2024-30421, discovered through global website indexing conducted by WebTechSurvey.
Events Manager for WordPress is susceptible to CVE-2024-30421 vulnerability.
Events Manager for WordPress versions before, and including, 6.4.7.1 are vulnerable to CVE-2024-30421.