CVE-2024-43277

WordPress UsersWP plugin <= 1.2.15 - Broken Access Control vulnerability

Missing Authorization vulnerability in AyeCode Ltd UsersWP allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UsersWP: from n/a through 1.2.15.


We have discovered 519 live websites that are affected by CVE-2024-43277.

Run a Free Instant Scan




Affected Software

Product  Userswp
Category Wordpress Plugins
Vulnerable Domains519 live websites (15% of Userswp install base)
Vulnerable Versions
  • from 0 through 1.2.15
Vulnerable Versions Count53 versions ( 58% of all versions)


Common Weakness Enumeration

CWE-862 Missing Authorization



Details

  • Published - Nov 1, 2024
  • Updated - Nov 5, 2024

Credits

  • Ananda Dhakal (Patchstack) (finder)

Website Distribution by Country

Number of websites using CVE-2024-43277
United States157 websites



Germany50 websites
Italy40 websites
GB35 websites
Spain23 websites
Russia23 websites
France21 websites
Poland20 websites
South Africa12 websites
Canada11 websites

Website Distribution by TLD

Number of websites using CVE-2024-43277
.com194 websites
.org48 websites
.it27 websites
.de22 websites
.ru20 websites
.co.uk19 websites
.pl17 websites
.net15 websites
.eu9 websites
.fr8 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-43277

Top websites that are affected by CVE-2024-43277. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**.today United States***,***
************.com United States***,***
*****.org United States***,***
******.com Cyprus***,***
*****.org Belgium***,***
************.com Canada***,***
*************.com United States***,***
****.ong Portugal***,***
*****.com United States***,***
*************.org Spain***,***
See full domain list

FAQ

CVE-2024-43277 is Missing Authorization in Userswp
A total of 519 websites have been identified as vulnerable to CVE-2024-43277, based on global website indexing conducted by WebTechSurvey.
The Userswp is affected by the CVE-2024-43277 vulnerability.
Userswp versions up to and including 1.2.15 are vulnerable to CVE-2024-43277.