CVE-2024-8107

Slider Revolution <= 6.7.18 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload

The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 6.7.18 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file. By default, this can only be exploited by administrators, but the ability to use and configure Slider Revolution can be extended to authors.


We have discovered 966,253 live websites that are affected by CVE-2024-8107.

Run a Free Instant Scan




Affected Software

Product  Revslider
Category UI Frameworks
Vulnerable Domains966,253 live websites (73% of Revslider install base)
Vulnerable Versions
  • from 0 through 6.7.18
Vulnerable Versions Count343 versions ( 84% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Oct 1, 2024
  • Updated - Apr 8, 2026

Credits

  • wesley (finder)

Website Distribution by Country

Number of websites using CVE-2024-8107
United States240,383 websites



Germany94,603 websites
Italy64,979 websites
France55,903 websites
GB42,580 websites
Spain36,723 websites
Turkey26,843 websites
Netherlands26,259 websites
Poland24,859 websites
Brazil24,664 websites

Website Distribution by TLD

Number of websites using CVE-2024-8107
.com398,858 websites
.de51,100 websites
.it46,291 websites
.org34,120 websites
.co.uk24,866 websites
.com.br23,665 websites
.nl22,775 websites
.fr22,134 websites
.pl18,792 websites
.net17,986 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-8107

Top websites that are affected by CVE-2024-8107. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******.com France*,***
***********.eu Cyprus*,***
****.edu United States*,***
************.com Singapore*,***
******************.org United States*,***
************.ie United States*,***
**********.org United States*,***
********************.com Cyprus*,***
******************.cat Spain*,***
*****************.com United States*,***
See full domain list

FAQ

CVE-2024-8107 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Revslider
A total of 966,253 websites have been identified as vulnerable to CVE-2024-8107, based on global website indexing conducted by WebTechSurvey.
The Revslider is affected by the CVE-2024-8107 vulnerability.
Revslider versions up to and including 6.7.18 are vulnerable to CVE-2024-8107.