The wp-eMember WordPress plugin before 10.3.9 does not sanitize and escape the "fieldId" parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting.
We have discovered 462 live websites that are affected by CVE-2024-4749.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 462 live websites (62% of Wp eMember install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 54 versions ( 59% of all versions) |
| 234 websites | |
| 28 websites | |
| 26 websites | |
| 20 websites | |
| 19 websites | |
| 19 websites | |
| 18 websites | |
| 14 websites | |
| 13 websites | |
| 10 websites |
| .com | 232 websites |
| .org | 54 websites |
| .net | 13 websites |
| .co.uk | 13 websites |
| .ca | 12 websites |
| .com.au | 11 websites |
| .se | 9 websites |
| .nl | 9 websites |
| .it | 7 websites |
| .org.uk | 5 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ***********.org | **,*** | ||
| ************.org | **,*** | ||
| ***.com | ***,*** | ||
| **************.com | ***,*** | ||
| ****************.com | ***,*** | ||
| ********.com | ***,*** | ||
| *******.com | ***,*** | ||
| ************.ro | ***,*** | ||
| ***************.org | ***,*** | ||
| ****.org | ***,*** |
FAQ