The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 6.7.18 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file. By default, this can only be exploited by administrators, but the ability to use and configure Slider Revolution can be extended to authors.
We have discovered 966,253 live websites that are affected by CVE-2024-8107.
| Product | |
| Category | UI Frameworks |
| Vulnerable Domains | 966,253 live websites (73% of Revslider install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 343 versions ( 84% of all versions) |
| 240,383 websites | |
| 94,603 websites | |
| 64,979 websites | |
| 55,903 websites | |
| 42,580 websites | |
| 36,723 websites | |
| 26,843 websites | |
| 26,259 websites | |
| 24,859 websites | |
| 24,664 websites |
| .com | 398,858 websites |
| .de | 51,100 websites |
| .it | 46,291 websites |
| .org | 34,120 websites |
| .co.uk | 24,866 websites |
| .com.br | 23,665 websites |
| .nl | 22,775 websites |
| .fr | 22,134 websites |
| .pl | 18,792 websites |
| .net | 17,986 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ******.com | *,*** | ||
| ***********.eu | *,*** | ||
| ****.edu | *,*** | ||
| ************.com | *,*** | ||
| ******************.org | *,*** | ||
| ************.ie | *,*** | ||
| **********.org | *,*** | ||
| ********************.com | *,*** | ||
| ******************.cat | *,*** | ||
| *****************.com | *,*** |
FAQ