The wp-eMember WordPress plugin before v10.7.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack
We have discovered 581 live websites that are affected by CVE-2024-5081.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 581 live websites (77% of Wp eMember install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 73 versions ( 80% of all versions) |
| 289 websites | |
| 43 websites | |
| 29 websites | |
| 28 websites | |
| 27 websites | |
| 25 websites | |
| 23 websites | |
| 17 websites | |
| 16 websites | |
| 10 websites |
| .com | 296 websites |
| .org | 68 websites |
| .net | 18 websites |
| .co.uk | 17 websites |
| .ca | 15 websites |
| .com.au | 11 websites |
| .nl | 10 websites |
| .se | 9 websites |
| .org.uk | 9 websites |
| .it | 9 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ***********.org | **,*** | ||
| ************.org | **,*** | ||
| ***.com | ***,*** | ||
| **************.com | ***,*** | ||
| ****************.com | ***,*** | ||
| ********************.org | ***,*** | ||
| ********.com | ***,*** | ||
| *******.com | ***,*** | ||
| ***********.com | ***,*** | ||
| ************.ro | ***,*** |
FAQ