The BuddyPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘user_name’ parameter in versions up to, and including, 12.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 11,549 live websites that are affected by CVE-2024-3974.
Product | |
Category | Message Boards |
Vulnerable Domains | 11,549 live websites (63.09% of BuddyPress install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 115 versions ( 92.74% of all versions) |
![]() | 4,572 websites |
![]() | 1,163 websites |
![]() | 959 websites |
![]() | 463 websites |
![]() | 350 websites |
![]() | 320 websites |
![]() | 286 websites |
![]() | 263 websites |
![]() | 209 websites |
![]() | 174 websites |
.com | 4,665 websites |
.org | 1,293 websites |
.de | 462 websites |
.net | 414 websites |
.ru | 395 websites |
.fr | 282 websites |
.it | 266 websites |
.nl | 166 websites |
.co.uk | 166 websites |
.com.br | 162 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
******.com | ![]() | **,*** | |
**********.com | ![]() | **,*** | |
*********.*******.org | ![]() | **,*** | |
*****.*****.edu | ![]() | **,*** | |
*******.space | ![]() | **,*** | |
**********.com | ![]() | **,*** | |
*****.***.uk | ![]() | **,*** | |
**********.org | ![]() | **,*** | |
*****.io | ![]() | **,*** | |
*******.com | ![]() | **,*** |
FAQ