CVE-2024-31382

WordPress Blocksy theme <= 2.0.22 - Cross Site Request Forgery (CSRF) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in Creative Themes HQ Blocksy.This issue affects Blocksy: from n/a through 2.0.22.


We have discovered 9,311 live websites that are affected by CVE-2024-31382.

Test my site




Affected Software

Product  Blocksy
Category Wordpress Themes
Vulnerable Domains9,311 live websites (19.65% of Blocksy install base)
Vulnerable Versions
  • from 0 through 2.0.22
Vulnerable Versions Count208 versions ( 75.36% of all versions)


Common Weakness Enumeration

CWE-352 Cross-Site Request Forgery (CSRF)



Details

  • Published - Apr 15, 2024
  • Updated - Aug 8, 2024

Credits

  • Dhabaleshwar Das (Patchstack Alliance) (finder)

CVE-2024-31382 usage by Country

United States3,746 websites



Germany1,030 websites
France475 websites
Denmark351 websites
Poland339 websites
Netherlands327 websites
Cyprus323 websites
Italy235 websites
GB197 websites
Russia189 websites

CVE-2024-31382 usage by TLD

.com3,374 websites
.info482 websites
.de377 websites
.nl344 websites
.pl313 websites
.com.br300 websites
.org299 websites
.dk279 websites
.it229 websites
.net203 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-31382

Top websites that are affected by CVE-2024-31382. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**********.nl Netherlands**,***
******.net United States**,***
*********.org Spain**,***
*****.us Germany**,***
******.dk Denmark***,***
****.********.edu United States***,***
********.me United States***,***
*********.com Germany***,***
******.**.za United States***,***
**.pl Poland***,***
See full domain list

FAQ

CVE-2024-31382 is Cross-Site Request Forgery (CSRF) in Blocksy
A total of 9,311 websites have been identified as vulnerable to CVE-2024-31382, discovered through global website indexing conducted by WebTechSurvey.
Blocksy is susceptible to CVE-2024-31382 vulnerability.
Blocksy versions before, and including, 2.0.22 are vulnerable to CVE-2024-31382.