CVE-2024-7132

CoBlocks < 3.1.13 - Editor+ Stored XSS

The Page Builder Gutenberg Blocks WordPress plugin before 3.1.13 does not escape the content of post embed via one of its block, which could allow users with the capability to publish posts (editor and admin by default) to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)


We have discovered 279,937 live websites that are affected by CVE-2024-7132.

Test my site




Affected Software

Product  GoDaddy CoBlocks
Category Wordpress Plugins
Vulnerable Domains279,937 live websites (81.72% of GoDaddy CoBlocks install base)
Vulnerable Versions
  • from 0 before 3.1.13
Vulnerable Versions Count125 versions ( 97.66% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Aug 29, 2024
  • Updated - Aug 29, 2024

Credits

  • Dmitrii Ignatyev (finder)
  • WPScan (coordinator)

CVE-2024-7132 usage by Country

United States271,059 websites



Germany1,943 websites
GB1,343 websites
France513 websites
Japan476 websites
Netherlands436 websites
Switzerland320 websites
Canada286 websites
Italy260 websites
Australia245 websites

CVE-2024-7132 usage by TLD

.com205,035 websites
.org20,991 websites
.net9,699 websites
.co.uk4,245 websites
.ca3,121 websites
.fr1,732 websites
.de1,569 websites
.nl1,260 websites
.com.au1,201 websites
.ch862 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-7132

Top websites that are affected by CVE-2024-7132. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.com United States**
********.*********.com United States**
**********.com United States***
********.com United States*,***
*********.com United States*,***
*******.com United States*,***
***********.com United States*,***
**********.com United States*,***
********.org United States*,***
****************.com United States*,***
See full domain list

FAQ

CVE-2024-7132 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GoDaddy CoBlocks
A total of 279,937 websites have been identified as vulnerable to CVE-2024-7132, discovered through global website indexing conducted by WebTechSurvey.
GoDaddy CoBlocks is susceptible to CVE-2024-7132 vulnerability.
GoDaddy CoBlocks versions before 3.1.13 are vulnerable to CVE-2024-7132.
Version 3.1.13 of GoDaddy CoBlocks addresses the CVE-2024-7132 security vulnerability.