The WP ULike WordPress plugin before 4.7.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
We have discovered 7,059 live websites that are affected by CVE-2024-7878.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 7,059 live websites (55.75% of WP ULike install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 82 versions ( 90.11% of all versions) |
![]() | 2,016 websites |
![]() | 908 websites |
![]() | 706 websites |
![]() | 586 websites |
![]() | 339 websites |
![]() | 235 websites |
![]() | 174 websites |
![]() | 151 websites |
![]() | 141 websites |
![]() | 131 websites |
.com | 3,137 websites |
.ru | 636 websites |
.net | 290 websites |
.org | 238 websites |
.com.br | 225 websites |
.jp | 191 websites |
.de | 153 websites |
.pl | 142 websites |
.it | 94 websites |
.fr | 80 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*****.com | ![]() | *,*** | |
*************.com | ![]() | **,*** | |
****.com | ![]() | **,*** | |
************.com | ![]() | **,*** | |
**************.com | ![]() | **,*** | |
**********.ca | ![]() | **,*** | |
****.*********.com | ![]() | **,*** | |
*****************.com | ![]() | **,*** | |
*******************.org | ![]() | **,*** | |
****.******.jp | ![]() | ***,*** |
FAQ