The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘block_id’ parameter in versions up to, and including, 2.13.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 7,532 live websites that are affected by CVE-2024-4366.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 7,532 live websites (13.29% of Spectra install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 140 versions ( 82.84% of all versions) |
![]() | 2,907 websites |
![]() | 892 websites |
![]() | 553 websites |
![]() | 303 websites |
![]() | 255 websites |
![]() | 218 websites |
![]() | 217 websites |
![]() | 154 websites |
![]() | 143 websites |
![]() | 117 websites |
.com | 3,380 websites |
.de | 419 websites |
.org | 399 websites |
.net | 218 websites |
.fr | 194 websites |
.co.uk | 194 websites |
.pl | 178 websites |
.nl | 150 websites |
.com.br | 150 websites |
.es | 125 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
********.com | ![]() | **,*** | |
*************.com | ![]() | **,*** | |
***.com | ![]() | **,*** | |
************.com | ![]() | **,*** | |
******************.com | ![]() | **,*** | |
**********.org | ![]() | ***,*** | |
*******.com | ![]() | ***,*** | |
******.com | ![]() | ***,*** | |
***********.com | ![]() | ***,*** | |
*********.com | ![]() | ***,*** |