CVE-2024-5090

SiteOrigin Widgets Bundle <= 1.61.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via SiteOrigin Blog Widget

The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's SiteOrigin Blog Widget in all versions up to, and including, 1.61.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.


We have discovered 38,685 live websites that are affected by CVE-2024-5090.

Test my site




Affected Software

Product  So Widgets Bundle
Category Wordpress Plugins
Vulnerable Domains38,685 live websites (44.94% of So Widgets Bundle install base)
Vulnerable Versions
  • from 0 through 1.61.1
Vulnerable Versions Count193 versions ( 84.65% of all versions)



Details

  • Published - Jun 11, 2024
  • Updated - Aug 1, 2024

Credits

  • Ngô Thiên An (finder)

CVE-2024-5090 usage by Country

United States8,813 websites



Germany5,386 websites
France2,844 websites
Japan1,993 websites
GB1,843 websites
Netherlands1,662 websites
Poland1,565 websites
Russia1,413 websites
Italy1,101 websites
Spain946 websites

CVE-2024-5090 usage by TLD

.com13,681 websites
.de2,972 websites
.nl1,644 websites
.org1,590 websites
.co.uk1,363 websites
.pl1,243 websites
.ru1,146 websites
.fr1,111 websites
.it865 websites
.net810 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-5090

Top websites that are affected by CVE-2024-5090. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.*************.com United States*,***
****.***.tr Turkey**,***
*************.com United States**,***
*****************.com United States**,***
***********.com United States**,***
*********.org United States**,***
******.org United States**,***
*********.com Indonesia**,***
****.**.th Thailand**,***
***.it France**,***
See full domain list

FAQ

A total of 38,685 websites have been identified as vulnerable to CVE-2024-5090, discovered through global website indexing conducted by WebTechSurvey.
So Widgets Bundle is susceptible to CVE-2024-5090 vulnerability.
So Widgets Bundle versions before, and including, 1.61.1 are vulnerable to CVE-2024-5090.