The Easy Table of Contents WordPress plugin before 2.0.67.1 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.
We have discovered 29,818 live websites that are affected by CVE-2024-6334.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 29,818 live websites (28.55% of Easy Table of Contents install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 98 versions ( 91.59% of all versions) |
![]() | 11,275 websites |
![]() | 3,414 websites |
![]() | 2,330 websites |
![]() | 1,994 websites |
![]() | 1,738 websites |
![]() | 1,663 websites |
![]() | 906 websites |
![]() | 762 websites |
![]() | 629 websites |
![]() | 421 websites |
.com | 14,444 websites |
.ru | 1,759 websites |
.net | 1,437 websites |
.org | 1,131 websites |
.pl | 945 websites |
.de | 820 websites |
.fr | 661 websites |
.jp | 585 websites |
.es | 423 websites |
.info | 389 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*******.com | ![]() | *,*** | |
**********.com | ![]() | *,*** | |
*****.com | ![]() | *,*** | |
*********.com | ![]() | *,*** | |
*********.com | ![]() | **,*** | |
**************.com | ![]() | **,*** | |
**********.info | ![]() | **,*** | |
******.com | ![]() | **,*** | |
******.com | ![]() | **,*** | |
*********.net | ![]() | **,*** |
FAQ