CVE-2024-5081

WP eMember <= v10.7.0 - Stored XSS via CSRF

The wp-eMember WordPress plugin before v10.7.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack


We have discovered 581 live websites that are affected by CVE-2024-5081.

Run a Free Instant Scan




Affected Software

Product  Wp eMember
Category Wordpress Plugins
Vulnerable Domains581 live websites (77% of Wp eMember install base)
Vulnerable Versions
  • from 0 through 10.7
Vulnerable Versions Count73 versions ( 80% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Aug 5, 2024
  • Updated - Aug 5, 2024

Credits

  • Bob Matyas (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2024-5081
United States289 websites



GB43 websites
Germany29 websites
Hungary28 websites
Australia27 websites
France25 websites
Canada23 websites
Italy17 websites
Bulgaria16 websites
Sweden10 websites

Website Distribution by TLD

Number of websites using CVE-2024-5081
.com296 websites
.org68 websites
.net18 websites
.co.uk17 websites
.ca15 websites
.com.au11 websites
.nl10 websites
.se9 websites
.org.uk9 websites
.it9 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-5081

Top websites that are affected by CVE-2024-5081. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***********.org United States**,***
************.org United States**,***
***.com United States***,***
**************.com United States***,***
****************.com United States***,***
********************.org Germany***,***
********.com United States***,***
*******.com United States***,***
***********.com United States***,***
************.ro Germany***,***
See full domain list

FAQ

CVE-2024-5081 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Wp eMember
A total of 581 websites have been identified as vulnerable to CVE-2024-5081, based on global website indexing conducted by WebTechSurvey.
The Wp eMember is affected by the CVE-2024-5081 vulnerability.
Wp eMember versions up to 10.7 are vulnerable to CVE-2024-5081.
CVE-2024-5081 is resolved in version 10.7 of Wp eMember.