The Redux Framework plugin for WordPress is vulnerable to unauthenticated JSON file uploads due to missing authorization and capability checks on the Redux_Color_Scheme_Import function in versions 4.4.12 to 4.4.17. This makes it possible for unauthenticated attackers to upload JSON files, which can be used to conduct stored cross-site scripting attacks and, in some rare cases, when the wp_filesystem fails to initialize - to Remote Code Execution.
We have discovered 29,835 live websites that are affected by CVE-2024-6828.
Product | |
Category | JavaScript Frameworks |
Vulnerable Domains | 29,835 live websites (10.35% of Redux Framework install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 10 versions ( 5.88% of all versions) |
![]() | 10,461 websites |
![]() | 3,516 websites |
![]() | 1,872 websites |
![]() | 1,372 websites |
![]() | 1,069 websites |
![]() | 806 websites |
![]() | 689 websites |
![]() | 669 websites |
![]() | 636 websites |
![]() | 572 websites |
.com | 13,497 websites |
.org | 1,237 websites |
.de | 1,125 websites |
.it | 741 websites |
.co.uk | 681 websites |
.com.br | 677 websites |
.net | 661 websites |
.pl | 599 websites |
.fr | 590 websites |
.nl | 577 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*****.pl | ![]() | *,*** | |
*******************.nl | ![]() | **,*** | |
***.ai | ![]() | **,*** | |
************.com | ![]() | **,*** | |
****.**.tt | ![]() | **,*** | |
*****************.pl | ![]() | **,*** | |
**********************.com | ![]() | **,*** | |
************.de | ![]() | **,*** | |
***********.io | ![]() | **,*** | |
***************.de | ![]() | **,*** |
FAQ