CVE-2024-4749

WP eMember < 10.3.9 - Reflected XSS

The wp-eMember WordPress plugin before 10.3.9 does not sanitize and escape the "fieldId" parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting.


We have discovered 462 live websites that are affected by CVE-2024-4749.

Run a Free Instant Scan




Affected Software

Product  Wp eMember
Category Wordpress Plugins
Vulnerable Domains462 live websites (62% of Wp eMember install base)
Vulnerable Versions
  • from 0 through 10.3.9
Vulnerable Versions Count54 versions ( 59% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Jun 4, 2024
  • Updated - Aug 1, 2024

Credits

  • kauenavarro (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2024-4749
United States234 websites



GB28 websites
Australia26 websites
Hungary20 websites
Canada19 websites
Germany19 websites
France18 websites
Bulgaria14 websites
Italy13 websites
Sweden10 websites

Website Distribution by TLD

Number of websites using CVE-2024-4749
.com232 websites
.org54 websites
.net13 websites
.co.uk13 websites
.ca12 websites
.com.au11 websites
.se9 websites
.nl9 websites
.it7 websites
.org.uk5 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-4749

Top websites that are affected by CVE-2024-4749. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***********.org United States**,***
************.org United States**,***
***.com United States***,***
**************.com United States***,***
****************.com United States***,***
********.com United States***,***
*******.com United States***,***
************.ro Germany***,***
***************.org France***,***
****.org Bulgaria***,***
See full domain list

FAQ

CVE-2024-4749 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Wp eMember
A total of 462 websites have been identified as vulnerable to CVE-2024-4749, based on global website indexing conducted by WebTechSurvey.
The Wp eMember is affected by the CVE-2024-4749 vulnerability.
Wp eMember versions up to 10.3.9 are vulnerable to CVE-2024-4749.
CVE-2024-4749 is resolved in version 10.3.9 of Wp eMember.