The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's SiteOrigin Blog Widget in all versions up to, and including, 1.61.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 38,685 live websites that are affected by CVE-2024-5090.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 38,685 live websites (44.94% of So Widgets Bundle install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 193 versions ( 84.65% of all versions) |
![]() | 8,813 websites |
![]() | 5,386 websites |
![]() | 2,844 websites |
![]() | 1,993 websites |
![]() | 1,843 websites |
![]() | 1,662 websites |
![]() | 1,565 websites |
![]() | 1,413 websites |
![]() | 1,101 websites |
![]() | 946 websites |
.com | 13,681 websites |
.de | 2,972 websites |
.nl | 1,644 websites |
.org | 1,590 websites |
.co.uk | 1,363 websites |
.pl | 1,243 websites |
.ru | 1,146 websites |
.fr | 1,111 websites |
.it | 865 websites |
.net | 810 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
****.*************.com | ![]() | *,*** | |
****.***.tr | ![]() | **,*** | |
*************.com | ![]() | **,*** | |
*****************.com | ![]() | **,*** | |
***********.com | ![]() | **,*** | |
*********.org | ![]() | **,*** | |
******.org | ![]() | **,*** | |
*********.com | ![]() | **,*** | |
****.**.th | ![]() | **,*** | |
***.it | ![]() | **,*** |
FAQ