The The7 — Website and eCommerce Builder for WordPress theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url' attribute within the plugin's Icon and Heading widgets in all versions up to, and including, 11.13.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 44,090 live websites that are affected by CVE-2024-5451.
Product | |
Category | Wordpress Themes |
Vulnerable Domains | 44,090 live websites (50.30% of The7 install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 242 versions ( 90.64% of all versions) |
![]() | 12,992 websites |
![]() | 6,492 websites |
![]() | 3,095 websites |
![]() | 1,816 websites |
![]() | 1,662 websites |
![]() | 1,481 websites |
![]() | 1,430 websites |
![]() | 1,345 websites |
![]() | 972 websites |
![]() | 857 websites |
.com | 17,251 websites |
.de | 3,525 websites |
.org | 1,421 websites |
.nl | 1,420 websites |
.it | 1,407 websites |
.co.uk | 1,352 websites |
.ru | 1,094 websites |
.fr | 1,023 websites |
.es | 979 websites |
.com.br | 944 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
**********.com | ![]() | **,*** | |
**********.fr | ![]() | **,*** | |
*******.com | ![]() | **,*** | |
*******.com | ![]() | **,*** | |
****.********.com | ![]() | **,*** | |
****************.org | ![]() | **,*** | |
*******.com | ![]() | **,*** | |
*******.hu | ![]() | **,*** | |
*************.com | ![]() | **,*** | |
*********.com | ![]() | **,*** |