The All in One SEO WordPress plugin before 4.6.1.1 does not validate and escape some of its Post fields before outputting them back, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
We have discovered 293,276 live websites that are affected by CVE-2024-3368.
| Product | |
| Category | Search Engine Optimization |
| Vulnerable Domains | 293,276 live websites (33% of All in One SEO Pack install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 247 versions ( 82% of all versions) |
| 57,788 websites | |
| 88,512 websites | |
| 22,189 websites | |
| 17,546 websites | |
| 10,477 websites | |
| 7,587 websites | |
| 7,531 websites | |
| 7,412 websites | |
| 4,447 websites |
| .com | 126,289 websites |
| .ru | 21,195 websites |
| .jp | 19,219 websites |
| .net | 13,017 websites |
| .co.jp | 12,413 websites |
| .org | 9,395 websites |
| .de | 8,857 websites |
| .pl | 5,728 websites |
| .it | 5,202 websites |
| .co.uk | 5,098 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *****.net | *** | ||
| *********.com | *,*** | ||
| ******.at | *,*** | ||
| ****.com | *,*** | ||
| *****.com | *,*** | ||
| *********.com | *,*** | ||
| ******.com | *,*** | ||
| *******.io | *,*** | ||
| ***************.com | *,*** | ||
| ******************.com | *,*** |
FAQ