CVE-2024-43234

WordPress Woffice theme <= 5.4.14 - Unauthenticated Account Takeover vulnerability

Authentication Bypass Using an Alternate Path or Channel vulnerability in WofficeIO Woffice allows Authentication Bypass.This issue affects Woffice: from n/a through 5.4.14.


We have discovered 420 live websites that are affected by CVE-2024-43234.

Run a Free Instant Scan




Affected Software

Product  Woffice
Category Wordpress Themes
Vulnerable Domains420 live websites (100% of Woffice install base)
Vulnerable Versions
  • from 0 through 5.4.14
Vulnerable Versions Count0 versions ( less than 0.1% of all versions)


Common Weakness Enumeration

CWE-288 Authentication Bypass Using an Alternate Path or Channel



Details

  • Published - Dec 16, 2024
  • Updated - Dec 20, 2024

Credits

  • Rafie Muhammad (Patchstack) (finder)

Website Distribution by Country

Number of websites using CVE-2024-43234
United States124 websites



France55 websites
Germany35 websites
Netherlands27 websites
Portugal24 websites
Australia22 websites
Spain20 websites
Italy14 websites
GB14 websites
Brazil10 websites

Website Distribution by TLD

Number of websites using CVE-2024-43234
.com144 websites
.org37 websites
.fr24 websites
.com.au18 websites
.de17 websites
.nl14 websites
.es13 websites
.net13 websites
.eu10 websites
.it6 websites

Websites affected by CVE-2024-43234

Top websites that are affected by CVE-2024-43234. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.com Italy***,***
********.**********.com GB***,***
*****.*******.com France***,***
***************.de Germany***,***
*******.pt Portugal***,***
**.**************.pt Portugal*,***,***
**********.com United States*,***,***
*******************************.fr France*,***,***
*****.***.br Brazil*,***,***
****.*********.it Italy*,***,***
See full domain list

FAQ

CVE-2024-43234 is Authentication Bypass Using an Alternate Path or Channel in Woffice
A total of 420 websites have been identified as vulnerable to CVE-2024-43234, based on global website indexing conducted by WebTechSurvey.
The Woffice is affected by the CVE-2024-43234 vulnerability.
Woffice versions up to and including 5.4.14 are vulnerable to CVE-2024-43234.