The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button Group module in all versions up to, and including, 2.8.3.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 68,299 live websites that are affected by CVE-2024-9049.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 68,299 live websites (46.12% of Beaver Builder install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 313 versions ( 96.01% of all versions) |
![]() | 48,036 websites |
![]() | 2,906 websites |
![]() | 2,438 websites |
![]() | 2,224 websites |
![]() | 1,703 websites |
![]() | 1,154 websites |
![]() | 1,143 websites |
![]() | 1,098 websites |
![]() | 787 websites |
![]() | 719 websites |
.com | 45,286 websites |
.org | 3,988 websites |
.co.uk | 2,026 websites |
.net | 1,691 websites |
.com.au | 1,676 websites |
.de | 1,612 websites |
.ca | 1,229 websites |
.nl | 1,196 websites |
.fr | 1,073 websites |
.jp | 481 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
********.com | ![]() | *,*** | |
*****************.com | ![]() | **,*** | |
*******.com | ![]() | **,*** | |
*********.org | ![]() | **,*** | |
**********.com | ![]() | **,*** | |
**********.com | ![]() | **,*** | |
********.com | ![]() | **,*** | |
*******.com | ![]() | **,*** | |
*******.nl | ![]() | **,*** | |
********.com | ![]() | **,*** |
FAQ