The Absolute Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Name' field of a custom post criteria in all versions up to, and including, 1.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 453 live websites that are affected by CVE-2024-8965.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 453 live websites (27% of Absolute Reviews install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 9 versions ( 75% of all versions) |
| 130 websites | |
| 83 websites | |
| 43 websites | |
| 27 websites | |
| 15 websites | |
| 15 websites | |
| 13 websites | |
| 12 websites | |
| 11 websites | |
| 10 websites |
| .com | 173 websites |
| .pl | 72 websites |
| .org | 26 websites |
| .de | 15 websites |
| .net | 12 websites |
| .ru | 10 websites |
| .nl | 9 websites |
| .it | 7 websites |
| .ca | 6 websites |
| .fr | 5 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *****************.org | ***,*** | ||
| ***********.com | ***,*** | ||
| *******.*******.net | ***,*** | ||
| ********.com | ***,*** | ||
| *******.com | ***,*** | ||
| *************.com | ***,*** | ||
| **********.***.uk | ***,*** | ||
| ********.com | ***,*** | ||
| ********.com | ***,*** | ||
| ************.com | ***,*** |
FAQ