The TablePress – Tables in WordPress made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the table cell content in all versions up to, and including, 2.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 58,038 live websites that are affected by CVE-2024-9595.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 58,038 live websites (32% of TablePress install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 48 versions ( 70% of all versions) |
| 11,761 websites | |
| 7,274 websites | |
| 6,342 websites | |
| 4,379 websites | |
| 3,202 websites | |
| 2,237 websites | |
| 2,212 websites | |
| 1,538 websites | |
| 1,491 websites | |
| 865 websites |
| .com | 19,352 websites |
| .de | 4,870 websites |
| .ru | 3,617 websites |
| .org | 2,940 websites |
| .net | 1,788 websites |
| .it | 1,606 websites |
| .fr | 1,495 websites |
| .jp | 1,437 websites |
| .nl | 1,310 websites |
| .co.uk | 1,287 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ***************.org | *** | ||
| ****.br | *** | ||
| *****.net | *** | ||
| ****.******.com | *** | ||
| *****.com | *,*** | ||
| ***.***.edu | *,*** | ||
| *****.com | *,*** | ||
| *********.org | **,*** | ||
| *******************.ro | **,*** | ||
| ****.****.br | **,*** |
FAQ