The Content Views – Post Grid & Filter, Recent Posts, Category Posts, & More (Gutenberg Blocks and Shortcode) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Widget Post Overlay block in all versions up to, and including, 3.7.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 5,950 live websites that are affected by CVE-2024-3929.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 5,950 live websites (14% of Content Views install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 72 versions ( 88% of all versions) |
| 1,367 websites | |
| 613 websites | |
| 406 websites | |
| 326 websites | |
| 287 websites | |
| 284 websites | |
| 228 websites | |
| 195 websites | |
| 169 websites | |
| 152 websites |
| .com | 2,120 websites |
| .ru | 499 websites |
| .org | 404 websites |
| .it | 221 websites |
| .nl | 208 websites |
| .de | 193 websites |
| .net | 170 websites |
| .co.uk | 109 websites |
| .pl | 92 websites |
| .fr | 89 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *****.app | **,*** | ||
| *********.com | **,*** | ||
| **********.com | **,*** | ||
| ******.org | ***,*** | ||
| ****.***.gr | ***,*** | ||
| **********.com | ***,*** | ||
| *******.***.za | ***,*** | ||
| *******.******.ru | ***,*** | ||
| ***********.com | ***,*** | ||
| **************.com | ***,*** |
FAQ