CVE-2024-8721

Tracking Code Manager <= 2.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Tracking Code Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the tracking code field in all versions up to, and including, 2.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.


We have discovered 15,326 live websites that are affected by CVE-2024-8721.

Test my site




Affected Software

Product  Tracking Code Manager
Category Wordpress Plugins
Vulnerable Domains15,326 live websites (49.27% of Tracking Code Manager install base)
Vulnerable Versions
  • from 0 through 2.3
Vulnerable Versions Count5 versions ( 83.33% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Dec 24, 2024
  • Updated - Dec 24, 2024

Credits

  • TANG Cheuk Hei (finder)

CVE-2024-8721 usage by Country

United States7,655 websites



Germany1,134 websites
France568 websites
Australia545 websites
Brazil499 websites
Poland457 websites
GB420 websites
Spain397 websites
Israel361 websites
Italy312 websites

CVE-2024-8721 usage by TLD

.com7,495 websites
.com.au873 websites
.com.br771 websites
.de414 websites
.pl394 websites
.co.uk380 websites
.org359 websites
.it314 websites
.ca260 websites
.net259 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-8721

Top websites that are affected by CVE-2024-8721. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******.*********.com United States*,***
***********.com Germany**,***
**********.com United States**,***
*********.***.uk United States**,***
*********.com United States**,***
********.com United States**,***
*****.com United States**,***
***********.com United States**,***
***********.com United States**,***
********.com United States**,***
See full domain list

FAQ

CVE-2024-8721 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Tracking Code Manager
A total of 15,326 websites have been identified as vulnerable to CVE-2024-8721, discovered through global website indexing conducted by WebTechSurvey.
Tracking Code Manager is susceptible to CVE-2024-8721 vulnerability.
Tracking Code Manager versions before, and including, 2.3 are vulnerable to CVE-2024-8721.