CVE-2024-8629

WooCommerce Multilingual & Multicurrency with WPML <= 5.3.7 - Reflected Cross-Site Scripting

The WooCommerce Multilingual & Multicurrency with WPML plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 5.3.7. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.


We have discovered 21,744 live websites that are affected by CVE-2024-8629.

Test my site




Affected Software

Product  WooCommerce Multilingual
Category Wordpress Plugins
Vulnerable Domains21,744 live websites (48.22% of WooCommerce Multilingual install base)
Vulnerable Versions
  • from 0 through 5.3.7
Vulnerable Versions Count149 versions ( 94.30% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Oct 8, 2024
  • Updated - Oct 8, 2024

Credits

  • Dale Mavers (finder)

CVE-2024-8629 usage by Country

United States4,199 websites



Germany2,889 websites
France2,003 websites
Italy1,574 websites
Spain1,174 websites
Poland651 websites
Switzerland636 websites
Greece633 websites
Netherlands631 websites
Estonia459 websites

CVE-2024-8629 usage by TLD

.com9,795 websites
.it1,262 websites
.de635 websites
.eu567 websites
.ch452 websites
.es421 websites
.nl391 websites
.pl381 websites
.fr341 websites
.ca338 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-8629

Top websites that are affected by CVE-2024-8629. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.me United States*,***
***********.com United States**,***
***************.com United States**,***
*******************.es Spain**,***
*************.ca Canada**,***
*********.com Israel**,***
**********.com United States**,***
*************.com United States**,***
********.com United States***,***
************.dk Denmark***,***
See full domain list

FAQ

CVE-2024-8629 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in WooCommerce Multilingual
A total of 21,744 websites have been identified as vulnerable to CVE-2024-8629, discovered through global website indexing conducted by WebTechSurvey.
WooCommerce Multilingual is susceptible to CVE-2024-8629 vulnerability.
WooCommerce Multilingual versions before, and including, 5.3.7 are vulnerable to CVE-2024-8629.