The All in One SEO WordPress plugin before 4.6.1.1 does not validate and escape some of its Post fields before outputting them back, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
We have discovered 473,705 live websites that are affected by CVE-2024-3368.
Product | ![]() |
Category | Search Engine Optimization |
Vulnerable Domains | 473,705 live websites (43.76% of All in One SEO Pack install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 335 versions ( 90.30% of all versions) |
![]() | 114,873 websites |
![]() | 139,406 websites |
![]() | 32,959 websites |
![]() | 29,413 websites |
![]() | 18,924 websites |
![]() | 11,404 websites |
![]() | 11,193 websites |
![]() | 6,495 websites |
![]() | 6,486 websites |
.com | 217,203 websites |
.jp | 28,878 websites |
.ru | 27,212 websites |
.net | 21,221 websites |
.co.jp | 17,277 websites |
.org | 15,442 websites |
.de | 13,722 websites |
.pl | 9,228 websites |
.co.uk | 8,401 websites |
.info | 5,930 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*****.net | ![]() | *** | |
*********.com | ![]() | *,*** | |
******.at | ![]() | *,*** | |
****.com | ![]() | *,*** | |
*****.com | ![]() | *,*** | |
***********.com | ![]() | *,*** | |
*********.com | ![]() | *,*** | |
******.com | ![]() | *,*** | |
*******.io | ![]() | *,*** | |
*************.org | ![]() | *,*** |
FAQ