CVE-2024-43309

WordPress WP Telegram Widget and Join Link plugin <= 2.1.27 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP Socio WP Telegram Widget and Join Link allows Stored XSS.This issue affects WP Telegram Widget and Join Link: from n/a through 2.1.27.


We have discovered 34 live websites that are affected by CVE-2024-43309.

Run a Free Instant Scan




Affected Software

Product  Wptelegram Widget
Category Wordpress Plugins
Vulnerable Domains34 live websites (100% of Wptelegram Widget install base)
Vulnerable Versions
  • from 0 through 2.1.27
Vulnerable Versions Count0 versions ( less than 0.1% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Aug 18, 2024
  • Updated - Aug 19, 2024

Credits

  • Muhammad Daffa (Patchstack Alliance) (finder)

Website Distribution by Country

Number of websites using CVE-2024-43309
United States5 websites



Russia7 websites
Italy5 websites
Ukraine4 websites
Brazil2 websites
Iran2 websites
Poland2 websites
Canada1 websites
Czech Republic1 websites
France1 websites

Website Distribution by TLD

Number of websites using CVE-2024-43309
.com7 websites
.ru7 websites
.it4 websites
.com.br1 websites
.cz1 websites
.info1 websites
.io1 websites
.org1 websites
.pl1 websites

Websites affected by CVE-2024-43309

Top websites that are affected by CVE-2024-43309. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***********.ru Russia*,***,***
**********.com Canada*,***,***
*********.***.br Brazil*,***,***
********.***.ua Ukraine**,***,***
****.***.ir Iran**,***,***
**************.***.ua Ukraine**,***,***
************.hu Hungary**,***,***
**********.cz Czech Republic**,***,***
***************.pl Poland**,***,***
***********.it Italy**,***,***
See full domain list

FAQ

CVE-2024-43309 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Wptelegram Widget
A total of 34 websites have been identified as vulnerable to CVE-2024-43309, based on global website indexing conducted by WebTechSurvey.
The Wptelegram Widget is affected by the CVE-2024-43309 vulnerability.
Wptelegram Widget versions up to and including 2.1.27 are vulnerable to CVE-2024-43309.