CVE-2024-4260

CoBlocks < 3.1.12 - Contributor+ SSRF

The Page Builder Gutenberg Blocks WordPress plugin before 3.1.12 does not prevent users from pinging arbitrary hosts via some of its shortcodes, which could allow high privilege users such as contributors to perform SSRF attacks.


We have discovered 279,270 live websites that are affected by CVE-2024-4260.

Test my site




Affected Software

Product  GoDaddy CoBlocks
Category Wordpress Plugins
Vulnerable Domains279,270 live websites (81.53% of GoDaddy CoBlocks install base)
Vulnerable Versions
  • from 0 before 3.1.12
Vulnerable Versions Count124 versions ( 96.88% of all versions)


Common Weakness Enumeration

CWE-918 Server-Side Request Forgery (SSRF)



Details

  • Published - Jul 23, 2024
  • Updated - Aug 1, 2024

Credits

  • Dmitrii Ignatyev (finder)
  • WPScan (coordinator)

CVE-2024-4260 usage by Country

United States270,590 websites



Germany1,887 websites
GB1,329 websites
France500 websites
Japan456 websites
Netherlands433 websites
Switzerland317 websites
Canada282 websites
Italy258 websites
Australia242 websites

CVE-2024-4260 usage by TLD

.com204,650 websites
.org20,941 websites
.net9,685 websites
.co.uk4,229 websites
.ca3,104 websites
.fr1,730 websites
.de1,538 websites
.nl1,256 websites
.com.au1,192 websites
.ch860 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-4260

Top websites that are affected by CVE-2024-4260. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.com United States**
********.*********.com United States**
**********.com United States***
********.com United States*,***
*********.com United States*,***
*******.com United States*,***
***********.com United States*,***
**********.com United States*,***
********.org United States*,***
****************.com United States*,***
See full domain list

FAQ

CVE-2024-4260 is Server-Side Request Forgery (SSRF) in GoDaddy CoBlocks
A total of 279,270 websites have been identified as vulnerable to CVE-2024-4260, discovered through global website indexing conducted by WebTechSurvey.
GoDaddy CoBlocks is susceptible to CVE-2024-4260 vulnerability.
GoDaddy CoBlocks versions before 3.1.12 are vulnerable to CVE-2024-4260.
Version 3.1.12 of GoDaddy CoBlocks addresses the CVE-2024-4260 security vulnerability.