CVE-2024-37500

WordPress Beaver Builder plugin <= 2.8.2.2 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Beaver Builder Team Beaver Builder allows Stored XSS.This issue affects Beaver Builder: from n/a through 2.8.2.2.


We have discovered 58,665 live websites that are affected by CVE-2024-37500.

Test my site




Affected Software

Product  Beaver Builder
Category Wordpress Plugins
Vulnerable Domains58,665 live websites (39.62% of Beaver Builder install base)
Vulnerable Versions
  • from 0 through 2.8.2.2
Vulnerable Versions Count306 versions ( 93.87% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Jul 21, 2024
  • Updated - Aug 2, 2024

Credits

  • João Pedro Soares de Alcântara - Kinorth (Patchstack Alliance) (finder)

CVE-2024-37500 usage by Country

United States41,431 websites



Germany2,454 websites
GB2,057 websites
Japan1,668 websites
France1,377 websites
Singapore1,032 websites
Australia958 websites
Netherlands925 websites
China786 websites
Canada605 websites

CVE-2024-37500 usage by TLD

.com39,631 websites
.org3,288 websites
.co.uk1,679 websites
.net1,452 websites
.com.au1,399 websites
.de1,374 websites
.ca1,042 websites
.nl965 websites
.jp469 websites
.fr463 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-37500

Top websites that are affected by CVE-2024-37500. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**********.com United States**,***
********.com United States**,***
*******.com United States**,***
**************.com United States**,***
****.ca United States**,***
****.net United States**,***
**********.com United States**,***
**************.com United States**,***
**************.org Singapore**,***
**********.com United States**,***
See full domain list

FAQ

CVE-2024-37500 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Beaver Builder
A total of 58,665 websites have been identified as vulnerable to CVE-2024-37500, discovered through global website indexing conducted by WebTechSurvey.
Beaver Builder is susceptible to CVE-2024-37500 vulnerability.
Beaver Builder versions before, and including, 2.8.2.2 are vulnerable to CVE-2024-37500.