CVE-2024-9947

ProfilePress - Pro <= 4.11.1 - Authentication Bypass via WordPress.com OAuth provider

The ProfilePress Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.11.1. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email and the user does not have an already-existing account for the service returning the token.


We have discovered 11,021 live websites that are affected by CVE-2024-9947.

Test my site




Affected Software

Product  ProfilePress
Category Wordpress Plugins
Vulnerable Domains11,021 live websites (19.84% of ProfilePress install base)
Vulnerable Versions
  • from 0 through 4.11.1
Vulnerable Versions Count75 versions ( 66.37% of all versions)


Common Weakness Enumeration

CWE-287 Improper Authentication



Details

  • Published - Oct 23, 2024
  • Updated - Feb 19, 2025

Credits

  • wesley (finder)

CVE-2024-9947 usage by Country

United States3,783 websites



Japan1,554 websites
Germany1,168 websites
France587 websites
Russia317 websites
Poland284 websites
GB281 websites
Brazil251 websites
Italy241 websites
Spain238 websites

CVE-2024-9947 usage by TLD

.com5,025 websites
.de540 websites
.org459 websites
.net418 websites
.com.br356 websites
.jp314 websites
.ru262 websites
.pl251 websites
.it220 websites
.co.uk181 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-9947

Top websites that are affected by CVE-2024-9947. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**********.com United States*,***
**********.com United States*,***
*********.com Japan**,***
****************.com United States**,***
************.com United States**,***
***************.net United States**,***
********.com United States**,***
************.com Japan**,***
*********.com United States**,***
***********.****.org United States**,***
See full domain list

FAQ

CVE-2024-9947 is Improper Authentication in ProfilePress
A total of 11,021 websites have been identified as vulnerable to CVE-2024-9947, discovered through global website indexing conducted by WebTechSurvey.
ProfilePress is susceptible to CVE-2024-9947 vulnerability.
ProfilePress versions before, and including, 4.11.1 are vulnerable to CVE-2024-9947.