CVE-2024-43320

WordPress WPBakery Page Builder Addons plugin <= 3.9 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Livemesh Livemesh Addons for WPBakery Page Builder addons-for-visual-composer allows Stored XSS.This issue affects Livemesh Addons for WPBakery Page Builder: from n/a through 3.9.


We have discovered 2,604 live websites that are affected by CVE-2024-43320.

Run a Free Instant Scan




Affected Software

Product  Addons For Visual Composer
Category Wordpress Plugins
Vulnerable Domains2,604 live websites (100% of Addons For Visual Composer install base)
Vulnerable Versions
  • from 0 through 3.9
Vulnerable Versions Count0 versions ( less than 0.1% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Aug 18, 2024
  • Updated - Aug 19, 2024

Credits

  • LVT-tholv2k (Patchstack Alliance) (finder)

Website Distribution by Country

Number of websites using CVE-2024-43320
United States531 websites



Germany278 websites
Italy222 websites
France175 websites
Russia130 websites
GB94 websites
Spain94 websites
Poland64 websites
Brazil63 websites
India53 websites

Website Distribution by TLD

Number of websites using CVE-2024-43320
.com1,007 websites
.it148 websites
.de138 websites
.org128 websites
.ru98 websites
.net66 websites
.com.br59 websites
.fr57 websites
.pl44 websites
.co.uk38 websites

Websites affected by CVE-2024-43320

Top websites that are affected by CVE-2024-43320. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******.org United States***,***
*******.org United States***,***
****.***.dz Algeria***,***
*****************.com United States***,***
***********.com United States***,***
*************.net United States***,***
*****************.org United States***,***
***********.org France***,***
*************.no Norway***,***
*****.ca Canada***,***
See full domain list

FAQ

CVE-2024-43320 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Addons For Visual Composer
A total of 2,604 websites have been identified as vulnerable to CVE-2024-43320, based on global website indexing conducted by WebTechSurvey.
The Addons For Visual Composer is affected by the CVE-2024-43320 vulnerability.
Addons For Visual Composer versions up to and including 3.9 are vulnerable to CVE-2024-43320.