CVE-2024-9488

Comments – wpDiscuz <= 7.6.24 - Authentication Bypass via WordPress.com OAuth provider

The Comments – wpDiscuz plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.6.24. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email and the user does not have an already-existing account for the service returning the token.


We have discovered 4,097 live websites that are affected by CVE-2024-9488.

Run a Free Instant Scan




Affected Software

Product  Wpdiscuz
Category Wordpress Plugins
Vulnerable Domains4,097 live websites (100% of Wpdiscuz install base)
Vulnerable Versions
  • from 0 through 7.6.24
Vulnerable Versions Count0 versions ( less than 0.1% of all versions)


Common Weakness Enumeration

CWE-288 Authentication Bypass Using an Alternate Path or Channel



Details

  • Published - Oct 25, 2024
  • Updated - Feb 19, 2025

Credits

  • wesley (finder)

Website Distribution by Country

Number of websites using CVE-2024-9488
United States963 websites



Russia733 websites
Poland366 websites
Vietnam248 websites
Germany230 websites
Iran182 websites
France158 websites
Brazil97 websites
Italy85 websites
GB75 websites

Website Distribution by TLD

Number of websites using CVE-2024-9488
.com1,476 websites
.ru638 websites
.pl313 websites
.net149 websites
.org128 websites
.com.br97 websites
.de73 websites
.it68 websites
.fr56 websites
.cz49 websites

Websites affected by CVE-2024-9488

Top websites that are affected by CVE-2024-9488. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**********.com United States**,***
*********.pl Poland**,***
**************.com United States**,***
********.com United States**,***
*******.com United States***,***
**************.de United States***,***
*******.com United States***,***
**********.com United States***,***
*********************.com United States***,***
************.co Poland***,***
See full domain list

FAQ

CVE-2024-9488 is Authentication Bypass Using an Alternate Path or Channel in Wpdiscuz
A total of 4,097 websites have been identified as vulnerable to CVE-2024-9488, based on global website indexing conducted by WebTechSurvey.
The Wpdiscuz is affected by the CVE-2024-9488 vulnerability.
Wpdiscuz versions up to and including 7.6.24 are vulnerable to CVE-2024-9488.