CVE-2024-9947

ProfilePress - Pro <= 4.11.1 - Authentication Bypass via WordPress.com OAuth provider

The ProfilePress Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.11.1. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email and the user does not have an already-existing account for the service returning the token.


We have discovered 7,668 live websites that are affected by CVE-2024-9947.

Run a Free Instant Scan




Affected Software

Product  ProfilePress
Category Wordpress Plugins
Vulnerable Domains7,668 live websites (16% of ProfilePress install base)
Vulnerable Versions
  • from 0 through 4.11.1
Vulnerable Versions Count72 versions ( 61% of all versions)


Common Weakness Enumeration

CWE-287 Improper Authentication



Details

  • Published - Oct 23, 2024
  • Updated - Feb 19, 2025

Credits

  • wesley (finder)

Website Distribution by Country

Number of websites using CVE-2024-9947
United States1,912 websites



Japan1,270 websites
Germany692 websites
France359 websites
Italy328 websites
Russia251 websites
GB249 websites
Spain236 websites
Brazil215 websites
Poland215 websites

Website Distribution by TLD

Number of websites using CVE-2024-9947
.com3,411 websites
.de369 websites
.net299 websites
.org299 websites
.it238 websites
.jp236 websites
.ru198 websites
.com.br196 websites
.pl173 websites
.es136 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-9947

Top websites that are affected by CVE-2024-9947. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.com Japan**,***
****************.com United States**,***
************.com United States**,***
************.com Japan**,***
*********.com United States**,***
***********.****.org United States**,***
**************.com United States**,***
***********.net Turkey**,***
***.sucks United States**,***
****************.com United States**,***
See full domain list

FAQ

CVE-2024-9947 is Improper Authentication in ProfilePress
A total of 7,668 websites have been identified as vulnerable to CVE-2024-9947, based on global website indexing conducted by WebTechSurvey.
The ProfilePress is affected by the CVE-2024-9947 vulnerability.
ProfilePress versions up to and including 4.11.1 are vulnerable to CVE-2024-9947.