it's possible for an attacker to gain administrative access without having any kind of account on the targeted site and perform unauthorized actions. This is due to improper logic flow on the user registration process.
We have discovered 5,896 live websites that are affected by CVE-2024-6695.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 5,896 live websites (42% of Profile Builder install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 167 versions ( 84% of all versions) |
| 1,867 websites | |
| 490 websites | |
| 440 websites | |
| 289 websites | |
| 287 websites | |
| 286 websites | |
| 175 websites | |
| 164 websites | |
| 151 websites | |
| 121 websites |
| .com | 2,411 websites |
| .org | 395 websites |
| .it | 347 websites |
| .ru | 237 websites |
| .de | 182 websites |
| .co.uk | 157 websites |
| .nl | 130 websites |
| .net | 122 websites |
| .fr | 110 websites |
| .com.br | 104 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *****.com | *,*** | ||
| ***********.com | **,*** | ||
| ********.dk | **,*** | ||
| ***********.com | **,*** | ||
| ********.com | **,*** | ||
| ********.org | **,*** | ||
| ***********.com | **,*** | ||
| ****************.com | **,*** | ||
| ****************.com | **,*** | ||
| ************************.org | **,*** |
FAQ