CVE-2024-31434

WordPress Newsletter plugin <= 8.0.6 - Cross Site Request Forgery (CSRF) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in Stefano Lissa & The Newsletter Team Newsletter.This issue affects Newsletter: from n/a through 8.0.6.


We have discovered 22,157 live websites that are affected by CVE-2024-31434.

Run a Free Instant Scan




Affected Software

Product  Newsletter
Category Wordpress Plugins
Vulnerable Domains22,157 live websites (26% of Newsletter install base)
Vulnerable Versions
  • from 0 through 8.0.6
Vulnerable Versions Count285 versions ( 75% of all versions)


Common Weakness Enumeration

CWE-352 Cross-Site Request Forgery (CSRF)



Details

  • Published - Apr 15, 2024
  • Updated - Aug 2, 2024

Credits

  • Dhabaleshwar Das (Patchstack Alliance) (finder)

Website Distribution by Country

Number of websites using CVE-2024-31434
United States4,971 websites



Germany2,942 websites
Italy2,013 websites
France1,790 websites
Poland932 websites
GB785 websites
Spain537 websites
Russia472 websites
Netherlands422 websites
Brazil413 websites

Website Distribution by TLD

Number of websites using CVE-2024-31434
.com8,382 websites
.de1,543 websites
.it1,374 websites
.org1,163 websites
.fr711 websites
.pl705 websites
.net472 websites
.co.uk378 websites
.eu369 websites
.com.br369 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-31434

Top websites that are affected by CVE-2024-31434. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**********.com United States*,***
*********.com United States*,***
**************.com United States**,***
******.com United States**,***
**********.com United States**,***
***************.com United States**,***
**********.com United States**,***
***********.com Israel**,***
********.***.au Australia**,***
**.ru Russia**,***
See full domain list

FAQ

CVE-2024-31434 is Cross-Site Request Forgery (CSRF) in Newsletter
A total of 22,157 websites have been identified as vulnerable to CVE-2024-31434, based on global website indexing conducted by WebTechSurvey.
The Newsletter is affected by the CVE-2024-31434 vulnerability.
Newsletter versions up to and including 8.0.6 are vulnerable to CVE-2024-31434.