CVE-2024-6408

Slider by 10Web < 1.2.57 - Editor+ Stored XSS

The Slider by 10Web WordPress plugin before 1.2.57 does not sanitise and escape its Slider Title, which could allow high privilege users such as editors and above to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed


We have discovered 6,698 live websites that are affected by CVE-2024-6408.

Test my site




Affected Software

Product  Slider Wd
Category Wordpress Plugins
Vulnerable Domains6,698 live websites (61.78% of Slider Wd install base)
Vulnerable Versions
  • from 0 before 1.2.57
Vulnerable Versions Count188 versions ( 61.84% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Jul 31, 2024
  • Updated - Jul 31, 2024

Credits

  • Dmitrii Ignatyev (finder)
  • WPScan (coordinator)

CVE-2024-6408 usage by Country

United States2,332 websites



Germany847 websites
France444 websites
GB292 websites
Poland268 websites
Netherlands204 websites
Russia195 websites
Italy165 websites
Japan159 websites
Spain108 websites

CVE-2024-6408 usage by TLD

.com2,684 websites
.org466 websites
.de463 websites
.co.uk197 websites
.pl196 websites
.nl184 websites
.net182 websites
.fr176 websites
.ru175 websites
.it138 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-6408

Top websites that are affected by CVE-2024-6408. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.***.gov United States**,***
*********************.com GB***,***
*************.org United States***,***
****.*****.edu United States***,***
******.com United States***,***
**********************.com ***,***
*************.it Italy***,***
******************.com United States***,***
**.**********************.com ***,***
********.nl Netherlands***,***
See full domain list

FAQ

CVE-2024-6408 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Slider Wd
A total of 6,698 websites have been identified as vulnerable to CVE-2024-6408, discovered through global website indexing conducted by WebTechSurvey.
Slider Wd is susceptible to CVE-2024-6408 vulnerability.
Slider Wd versions before 1.2.57 are vulnerable to CVE-2024-6408.
Version 1.2.57 of Slider Wd addresses the CVE-2024-6408 security vulnerability.