CVE-2024-4446

Content Views – Post Grid & Filter, Recent Posts, Category Posts, & More (Gutenberg Blocks and Shortcode) <= 3.7.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via pagingType Parameter

The Content Views – Post Grid & Filter, Recent Posts, Category Posts, & More (Gutenberg Blocks and Shortcode) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘pagingType’ parameter in all versions up to, and including, 3.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.


We have discovered 6,020 live websites that are affected by CVE-2024-4446.

Run a Free Instant Scan




Affected Software

Product  Content Views
Category Wordpress Plugins
Vulnerable Domains6,020 live websites (14% of Content Views install base)
Vulnerable Versions
  • from 0 through 3.7.1
Vulnerable Versions Count73 versions ( 89% of all versions)



Details

  • Published - May 9, 2024
  • Updated - Aug 1, 2024

Credits

  • wesley (finder)

Website Distribution by Country

Number of websites using CVE-2024-4446
United States1,383 websites



Russia617 websites
Germany412 websites
Italy329 websites
France288 websites
Japan288 websites
Netherlands236 websites
GB200 websites
Canada172 websites
Spain153 websites

Website Distribution by TLD

Number of websites using CVE-2024-4446
.com2,143 websites
.ru502 websites
.org408 websites
.it223 websites
.nl216 websites
.de196 websites
.net172 websites
.co.uk111 websites
.pl93 websites
.es89 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-4446

Top websites that are affected by CVE-2024-4446. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.app Bulgaria**,***
*********.com United States**,***
**********.com United States**,***
******.org United States***,***
****.***.gr Greece***,***
**********.com United States***,***
*******.***.za South Africa***,***
*******.******.ru Russia***,***
***********.com United States***,***
**************.com United States***,***
See full domain list

FAQ

A total of 6,020 websites have been identified as vulnerable to CVE-2024-4446, based on global website indexing conducted by WebTechSurvey.
The Content Views is affected by the CVE-2024-4446 vulnerability.
Content Views versions up to and including 3.7.1 are vulnerable to CVE-2024-4446.