CVE-2024-31111

WordPress Core < 6.5.5 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Automattic WordPress allows Stored XSS.This issue affects WordPress: from 6.5 through 6.5.4, from 6.4 through 6.4.4, from 6.3 through 6.3.4, from 6.2 through 6.2.5, from 6.1 through 6.1.6, from 6.0 through 6.0.8, from 5.9 through 5.9.9.


We have discovered 408,407 live websites that are affected by CVE-2024-31111.

Test my site




Affected Software

Product  WordPress
Category Content Management System
Vulnerable Domains408,407 live websites (4.43% of WordPress install base)
Vulnerable Versions
  • from 5.9 through 5.9.9
  • from 6 through 6.0.8
  • from 6.1 through 6.1.6
  • from 6.2 through 6.2.5
  • from 6.3 through 6.3.4
  • from 6.4 through 6.4.4
  • from 6.5 through 6.5.4
Vulnerable Versions Count48 versions ( 5.16% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Jun 25, 2024
  • Updated - Aug 2, 2024

Credits

  • Rafie Muhammad (Patchstack) (finder)

CVE-2024-31111 usage by Country

United States150,160 websites



Germany55,889 websites
France18,904 websites
Japan15,705 websites
Poland15,635 websites
GB13,847 websites
Netherlands10,802 websites
Russia10,542 websites
Cyprus9,805 websites
Spain8,239 websites

CVE-2024-31111 usage by TLD

.com165,049 websites
.de27,721 websites
.org17,731 websites
.pl13,248 websites
.nl11,804 websites
.net11,619 websites
.ru11,023 websites
.co.uk10,063 websites
.com.br7,962 websites
.it6,823 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-31111

Top websites that are affected by CVE-2024-31111. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***************.org United States***
******.com United States***
**********.ca Canada*,***
*****.pl Poland*,***
********.com United States*,***
********.com Singapore*,***
************.com United States*,***
************.com United States*,***
****.cc Cocos(Keeling) Island*,***
****.tv France*,***
See full domain list

FAQ

CVE-2024-31111 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in WordPress
A total of 408,407 websites have been identified as vulnerable to CVE-2024-31111, discovered through global website indexing conducted by WebTechSurvey.
WordPress is susceptible to CVE-2024-31111 vulnerability.
WordPress versions before, and including, 6.5.4 are vulnerable to CVE-2024-31111.