The Simple Calendar – Google Calendar Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.4.2. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
We have discovered 12,564 live websites that are affected by CVE-2024-8549.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 12,564 live websites (40.24% of Simple Calendar install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 100 versions ( 87.72% of all versions) |
![]() | 4,879 websites |
![]() | 1,604 websites |
![]() | 936 websites |
![]() | 750 websites |
![]() | 400 websites |
![]() | 325 websites |
![]() | 311 websites |
![]() | 297 websites |
![]() | 232 websites |
![]() | 219 websites |
.com | 3,749 websites |
.org | 2,354 websites |
.de | 1,048 websites |
.fr | 334 websites |
.net | 323 websites |
.nl | 301 websites |
.co.uk | 243 websites |
.ca | 226 websites |
.jp | 225 websites |
.at | 200 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*****.gov | ![]() | **,*** | |
*****.****.cat | ![]() | **,*** | |
*************.org | ![]() | **,*** | |
***.org | ![]() | **,*** | |
****.**.jp | ![]() | ***,*** | |
******.org | ![]() | ***,*** | |
****.org | ![]() | ***,*** | |
****.com | ![]() | ***,*** | |
*******.**.***.br | ![]() | ***,*** | |
**********.com | ![]() | ***,*** |
FAQ