CVE-2024-3974

BuddyPress <= 12.4.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting

The BuddyPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘user_name’ parameter in versions up to, and including, 12.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.


We have discovered 11,549 live websites that are affected by CVE-2024-3974.

Test my site




Affected Software

Product  BuddyPress
Category Message Boards
Vulnerable Domains11,549 live websites (63.09% of BuddyPress install base)
Vulnerable Versions
  • from 0 through 12.4
Vulnerable Versions Count115 versions ( 92.74% of all versions)



Details

  • Published - May 9, 2024
  • Updated - Aug 1, 2024

Credits

  • wesley (finder)

CVE-2024-3974 usage by Country

United States4,572 websites



Germany1,163 websites
France959 websites
Russia463 websites
GB350 websites
Italy320 websites
Japan286 websites
Spain263 websites
Netherlands209 websites
Cyprus174 websites

CVE-2024-3974 usage by TLD

.com4,665 websites
.org1,293 websites
.de462 websites
.net414 websites
.ru395 websites
.fr282 websites
.it266 websites
.nl166 websites
.co.uk166 websites
.com.br162 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-3974

Top websites that are affected by CVE-2024-3974. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******.com Singapore**,***
**********.com United States**,***
*********.*******.org United States**,***
*****.*****.edu United States**,***
*******.space United States**,***
**********.com United States**,***
*****.***.uk United States**,***
**********.org United States**,***
*****.io United States**,***
*******.com France**,***
See full domain list

FAQ

A total of 11,549 websites have been identified as vulnerable to CVE-2024-3974, discovered through global website indexing conducted by WebTechSurvey.
BuddyPress is susceptible to CVE-2024-3974 vulnerability.
BuddyPress versions before, and including, 12.4 are vulnerable to CVE-2024-3974.