The Page Builder Gutenberg Blocks WordPress plugin before 3.1.12 does not prevent users from pinging arbitrary hosts via some of its shortcodes, which could allow high privilege users such as contributors to perform SSRF attacks.
We have discovered 279,270 live websites that are affected by CVE-2024-4260.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 279,270 live websites (81.53% of GoDaddy CoBlocks install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 124 versions ( 96.88% of all versions) |
![]() | 270,590 websites |
![]() | 1,887 websites |
![]() | 1,329 websites |
![]() | 500 websites |
![]() | 456 websites |
![]() | 433 websites |
![]() | 317 websites |
![]() | 282 websites |
![]() | 258 websites |
![]() | 242 websites |
.com | 204,650 websites |
.org | 20,941 websites |
.net | 9,685 websites |
.co.uk | 4,229 websites |
.ca | 3,104 websites |
.fr | 1,730 websites |
.de | 1,538 websites |
.nl | 1,256 websites |
.com.au | 1,192 websites |
.ch | 860 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*********.com | ![]() | ** | |
********.*********.com | ![]() | ** | |
**********.com | ![]() | *** | |
********.com | ![]() | *,*** | |
*********.com | ![]() | *,*** | |
*******.com | ![]() | *,*** | |
***********.com | ![]() | *,*** | |
**********.com | ![]() | *,*** | |
********.org | ![]() | *,*** | |
****************.com | ![]() | *,*** |
FAQ