The Slider, Gallery, and Carousel by MetaSlider – Responsive WordPress Slideshows plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'metaslider' shortcode in all versions up to, and including, 3.70.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 44,239 live websites that are affected by CVE-2024-3285.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 44,239 live websites (34% of MetaSlider for WordPress install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 114 versions ( 83% of all versions) |
| 7,838 websites | |
| 8,317 websites | |
| 3,917 websites | |
| 2,577 websites | |
| 2,202 websites | |
| 1,819 websites | |
| 1,531 websites | |
| 1,340 websites | |
| 1,146 websites | |
| 1,090 websites |
| .com | 17,051 websites |
| .de | 2,518 websites |
| .jp | 2,376 websites |
| .ru | 2,141 websites |
| .org | 1,692 websites |
| .net | 1,279 websites |
| .it | 1,229 websites |
| .co.jp | 1,079 websites |
| .pl | 1,007 websites |
| .co.uk | 968 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| **********.ru | **,*** | ||
| **************.ca | **,*** | ||
| *********.**.jp | **,*** | ||
| ******.*******.**.jp | **,*** | ||
| ********.**.jp | **,*** | ||
| ****.************.org | **,*** | ||
| ****************.org | **,*** | ||
| *****.it | **,*** | ||
| *************.net | **,*** | ||
| ************.com | **,*** |
FAQ