CVE-2024-31434

WordPress Newsletter plugin <= 8.0.6 - Cross Site Request Forgery (CSRF) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in Stefano Lissa & The Newsletter Team Newsletter.This issue affects Newsletter: from n/a through 8.0.6.


We have discovered 32,045 live websites that are affected by CVE-2024-31434.

Test my site




Affected Software

Product  Newsletter
Category Wordpress Plugins
Vulnerable Domains32,045 live websites (36.14% of Newsletter install base)
Vulnerable Versions
  • from 0 through 8.0.6
Vulnerable Versions Count306 versions ( 82.70% of all versions)


Common Weakness Enumeration

CWE-352 Cross-Site Request Forgery (CSRF)



Details

  • Published - Apr 15, 2024
  • Updated - Aug 2, 2024

Credits

  • Dhabaleshwar Das (Patchstack Alliance) (finder)

CVE-2024-31434 usage by Country

United States9,638 websites



Germany4,819 websites
France2,682 websites
Italy1,441 websites
Poland1,372 websites
GB1,011 websites
Russia686 websites
Spain635 websites
Netherlands610 websites
Romania548 websites

CVE-2024-31434 usage by TLD

.com12,825 websites
.de2,200 websites
.org1,728 websites
.it1,105 websites
.pl1,094 websites
.fr956 websites
.net695 websites
.com.br619 websites
.co.uk581 websites
.ru532 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-31434

Top websites that are affected by CVE-2024-31434. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**********.com United States*,***
*********.com United States*,***
**************.com United States**,***
******.com United States**,***
************.sk Czech Republic**,***
***************.com United States**,***
*******************.com United States**,***
****.it Italy**,***
**********.com United States**,***
***********.com Netherlands**,***
See full domain list

FAQ

CVE-2024-31434 is Cross-Site Request Forgery (CSRF) in Newsletter
A total of 32,045 websites have been identified as vulnerable to CVE-2024-31434, discovered through global website indexing conducted by WebTechSurvey.
Newsletter is susceptible to CVE-2024-31434 vulnerability.
Newsletter versions before, and including, 8.0.6 are vulnerable to CVE-2024-31434.