CVE-2024-3368

All in One SEO < 4.6.1.1 - Contributor+ Stored XSS

The All in One SEO WordPress plugin before 4.6.1.1 does not validate and escape some of its Post fields before outputting them back, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks


We have discovered 473,705 live websites that are affected by CVE-2024-3368.

Test my site




Affected Software

Product  All in One SEO Pack
Category Search Engine Optimization
Vulnerable Domains473,705 live websites (43.76% of All in One SEO Pack install base)
Vulnerable Versions
  • from 0 before 4.6.1.1
Vulnerable Versions Count335 versions ( 90.30% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - May 20, 2024
  • Updated - Mar 14, 2025

Credits

  • Dmtirii Ignatyev (finder)
  • WPScan (coordinator)

CVE-2024-3368 usage by Country

United States114,873 websites



Japan139,406 websites
Germany32,959 websites
Russia29,413 websites
France18,924 websites
Poland11,404 websites
GB11,193 websites
Turkey6,495 websites
Cyprus6,486 websites

CVE-2024-3368 usage by TLD

.com217,203 websites
.jp28,878 websites
.ru27,212 websites
.net21,221 websites
.co.jp17,277 websites
.org15,442 websites
.de13,722 websites
.pl9,228 websites
.co.uk8,401 websites
.info5,930 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-3368

Top websites that are affected by CVE-2024-3368. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.net Singapore***
*********.com Italy*,***
******.at Germany*,***
****.com United States*,***
*****.com United States*,***
***********.com United States*,***
*********.com United States*,***
******.com United States*,***
*******.io Russia*,***
*************.org United States*,***
See full domain list

FAQ

CVE-2024-3368 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in All in One SEO Pack
A total of 473,705 websites have been identified as vulnerable to CVE-2024-3368, discovered through global website indexing conducted by WebTechSurvey.
All in One SEO Pack is susceptible to CVE-2024-3368 vulnerability.
All in One SEO Pack versions before 4.6.1.1 are vulnerable to CVE-2024-3368.
Version 4.6.1.1 of All in One SEO Pack addresses the CVE-2024-3368 security vulnerability.