CVE-2024-32548

WordPress What's New Generator plugin <= 2.0.2 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hideki Tanaka What's New Generator allows Stored XSS.This issue affects What's New Generator: from n/a through 2.0.2.


We have discovered 15,224 live websites that are affected by CVE-2024-32548.

Test my site




Affected Software

Product  Whats New Genarator
Category Wordpress Plugins
Vulnerable Domains15,224 live websites (99.97% of Whats New Genarator install base)
Vulnerable Versions
  • from 0 through 2.0.2
Vulnerable Versions Count7 versions ( 63.64% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Apr 17, 2024
  • Updated - Aug 2, 2024

Credits

  • CatFather (Patchstack Alliance) (finder)

CVE-2024-32548 usage by Country

United States405 websites



Japan14,042 websites
Canada14 websites
Singapore10 websites
China9 websites
France7 websites
Germany6 websites
Australia5 websites
GB5 websites

CVE-2024-32548 usage by TLD

.com7,618 websites
.jp2,939 websites
.co.jp1,877 websites
.net1,158 websites
.org519 websites
.info343 websites
.co10 websites
.ch3 websites
.co.uk3 websites
.com.cn3 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-32548

Top websites that are affected by CVE-2024-32548. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***********.com United States**,***
*****.**.jp Japan***,***
******.**.jp Japan***,***
************.**.jp Japan***,***
******.com United States***,***
*******.com Japan***,***
****.jp Japan***,***
******.jp Japan***,***
*******.**.jp Japan***,***
******************.com United States***,***
See full domain list

FAQ

CVE-2024-32548 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Whats New Genarator
A total of 15,224 websites have been identified as vulnerable to CVE-2024-32548, discovered through global website indexing conducted by WebTechSurvey.
Whats New Genarator is susceptible to CVE-2024-32548 vulnerability.
Whats New Genarator versions before, and including, 2.0.2 are vulnerable to CVE-2024-32548.