CVE-2024-35679

WordPress GiveWP plugin <= 3.12.0 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in GiveWP allows Reflected XSS.This issue affects GiveWP: from n/a through 3.12.0.


We have discovered 10,841 live websites that are affected by CVE-2024-35679.

Test my site




Affected Software

Product  GiveWP
Category Wordpress Plugins
Vulnerable Domains10,841 live websites (29.73% of GiveWP install base)
Vulnerable Versions
  • from 0 through 3.12
Vulnerable Versions Count205 versions ( 86.50% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Jun 8, 2024
  • Updated - Aug 2, 2024

Credits

  • Dimas Maulana (Patchstack Alliance) (finder)

CVE-2024-35679 usage by Country

United States5,017 websites



Germany1,165 websites
France663 websites
GB561 websites
Cyprus304 websites
Italy295 websites
Canada231 websites
Australia191 websites
Spain173 websites
South Africa146 websites

CVE-2024-35679 usage by TLD

.org4,250 websites
.com2,748 websites
.de299 websites
.it243 websites
.fr192 websites
.net188 websites
.ca183 websites
.org.uk176 websites
.co.uk155 websites
.nl96 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-35679

Top websites that are affected by CVE-2024-35679. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*************.sk United States**,***
********.org United States**,***
*********.org United States**,***
************.org United States**,***
****************.org Germany**,***
*******.org United States**,***
**************.com Australia**,***
****.org United States**,***
**********.net United States***,***
***.***.uk United States***,***
See full domain list

FAQ

CVE-2024-35679 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GiveWP
A total of 10,841 websites have been identified as vulnerable to CVE-2024-35679, discovered through global website indexing conducted by WebTechSurvey.
GiveWP is susceptible to CVE-2024-35679 vulnerability.
GiveWP versions before, and including, 3.12 are vulnerable to CVE-2024-35679.