The Page Builder Gutenberg Blocks WordPress plugin before 3.1.13 does not escape the content of post embed via one of its block, which could allow users with the capability to publish posts (editor and admin by default) to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
We have discovered 279,937 live websites that are affected by CVE-2024-7132.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 279,937 live websites (81.72% of GoDaddy CoBlocks install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 125 versions ( 97.66% of all versions) |
![]() | 271,059 websites |
![]() | 1,943 websites |
![]() | 1,343 websites |
![]() | 513 websites |
![]() | 476 websites |
![]() | 436 websites |
![]() | 320 websites |
![]() | 286 websites |
![]() | 260 websites |
![]() | 245 websites |
.com | 205,035 websites |
.org | 20,991 websites |
.net | 9,699 websites |
.co.uk | 4,245 websites |
.ca | 3,121 websites |
.fr | 1,732 websites |
.de | 1,569 websites |
.nl | 1,260 websites |
.com.au | 1,201 websites |
.ch | 862 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*********.com | ![]() | ** | |
********.*********.com | ![]() | ** | |
**********.com | ![]() | *** | |
********.com | ![]() | *,*** | |
*********.com | ![]() | *,*** | |
*******.com | ![]() | *,*** | |
***********.com | ![]() | *,*** | |
**********.com | ![]() | *,*** | |
********.org | ![]() | *,*** | |
****************.com | ![]() | *,*** |
FAQ