The WooCommerce Multilingual & Multicurrency with WPML plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 5.3.7. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
We have discovered 21,744 live websites that are affected by CVE-2024-8629.
Product | ![]() |
Category | Wordpress Plugins |
Vulnerable Domains | 21,744 live websites (48.22% of WooCommerce Multilingual install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 149 versions ( 94.30% of all versions) |
![]() | 4,199 websites |
![]() | 2,889 websites |
![]() | 2,003 websites |
![]() | 1,574 websites |
![]() | 1,174 websites |
![]() | 651 websites |
![]() | 636 websites |
![]() | 633 websites |
![]() | 631 websites |
![]() | 459 websites |
.com | 9,795 websites |
.it | 1,262 websites |
.de | 635 websites |
.eu | 567 websites |
.ch | 452 websites |
.es | 421 websites |
.nl | 391 websites |
.pl | 381 websites |
.fr | 341 websites |
.ca | 338 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*********.me | ![]() | *,*** | |
***********.com | ![]() | **,*** | |
***************.com | ![]() | **,*** | |
*******************.es | ![]() | **,*** | |
*************.ca | ![]() | **,*** | |
*********.com | ![]() | **,*** | |
**********.com | ![]() | **,*** | |
*************.com | ![]() | **,*** | |
********.com | ![]() | ***,*** | |
************.dk | ![]() | ***,*** |
FAQ