CVE-2024-30543

WordPress Whizzy plugin <= 1.1.18 - Insecure Direct Object References (IDOR) vulnerability

Authorization Bypass Through User-Controlled Key vulnerability in UPQODE Whizz.This issue affects Whizzy: from n/a through 1.1.18.


We have discovered 754 live websites that are affected by CVE-2024-30543.

Run a Free Instant Scan




Affected Software

Product  Whizzy
Category Wordpress Plugins
Vulnerable Domains754 live websites (100% of Whizzy install base)
Vulnerable Versions
  • from 0 through 1.1.18
Vulnerable Versions Count1 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-639 Authorization Bypass Through User-Controlled Key



Details

  • Published - Mar 31, 2024
  • Updated - Aug 2, 2024

Credits

  • Steven Julian (Patchstack Alliance) (finder)

Website Distribution by Country

Number of websites using CVE-2024-30543
United States156 websites



Germany129 websites
France76 websites
Italy75 websites
Poland27 websites
GB27 websites
Netherlands26 websites
Romania21 websites
Spain21 websites
Denmark17 websites

Website Distribution by TLD

Number of websites using CVE-2024-30543
.com383 websites
.de74 websites
.it40 websites
.fr27 websites
.nl23 websites
.pl19 websites
.net17 websites
.co.uk15 websites
.com.au10 websites
.ch9 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-30543

Top websites that are affected by CVE-2024-30543. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*************.ch Switzerland***,***
************.nl Netherlands*,***,***
*********.us United States*,***,***
************.com Spain*,***,***
****************.com United States*,***,***
**********.org United States*,***,***
************.com Turkey*,***,***
********.com Belgium*,***,***
**********.com France*,***,***
*************.com Germany*,***,***
See full domain list

FAQ

CVE-2024-30543 is Authorization Bypass Through User-Controlled Key in Whizzy
A total of 754 websites have been identified as vulnerable to CVE-2024-30543, based on global website indexing conducted by WebTechSurvey.
The Whizzy is affected by the CVE-2024-30543 vulnerability.
Whizzy versions up to and including 1.1.18 are vulnerable to CVE-2024-30543.