The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Grid widget in all versions up to, and including, 1.62.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 40,622 live websites that are affected by CVE-2024-5901.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 40,622 live websites (47.19% of So Widgets Bundle install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 196 versions ( 85.96% of all versions) |
![]() | 9,287 websites |
![]() | 5,696 websites |
![]() | 2,975 websites |
![]() | 2,069 websites |
![]() | 1,968 websites |
![]() | 1,757 websites |
![]() | 1,618 websites |
![]() | 1,472 websites |
![]() | 1,147 websites |
![]() | 981 websites |
.com | 14,354 websites |
.de | 3,148 websites |
.nl | 1,735 websites |
.org | 1,688 websites |
.co.uk | 1,463 websites |
.pl | 1,286 websites |
.ru | 1,195 websites |
.fr | 1,160 websites |
.it | 897 websites |
.net | 852 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
****.*************.com | ![]() | *,*** | |
****.***.tr | ![]() | **,*** | |
*************.com | ![]() | **,*** | |
*****************.com | ![]() | **,*** | |
***********.com | ![]() | **,*** | |
*****************.org | ![]() | **,*** | |
*********.org | ![]() | **,*** | |
******.org | ![]() | **,*** | |
*********.com | ![]() | **,*** | |
****.**.th | ![]() | **,*** |
FAQ