The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tagName’ parameter in versions up to, and including, 2.0.42 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 11,883 live websites that are affected by CVE-2024-4158.
Product | ![]() |
Category | Wordpress Themes |
Vulnerable Domains | 11,883 live websites (25.08% of Blocksy install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 227 versions ( 82.25% of all versions) |
![]() | 4,678 websites |
![]() | 1,341 websites |
![]() | 611 websites |
![]() | 472 websites |
![]() | 466 websites |
![]() | 400 websites |
![]() | 380 websites |
![]() | 304 websites |
![]() | 272 websites |
![]() | 239 websites |
.com | 4,487 websites |
.info | 494 websites |
.de | 490 websites |
.nl | 434 websites |
.pl | 415 websites |
.org | 412 websites |
.com.br | 390 websites |
.it | 301 websites |
.dk | 292 websites |
.net | 278 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
**********.nl | ![]() | **,*** | |
************.com | ![]() | **,*** | |
******.net | ![]() | **,*** | |
*********.org | ![]() | **,*** | |
*****.us | ![]() | **,*** | |
*******.it | ![]() | **,*** | |
******.dk | ![]() | ***,*** | |
****.********.edu | ![]() | ***,*** | |
********.me | ![]() | ***,*** | |
************.us | ![]() | ***,*** |