An Unrestricted File Upload Vulnerability in the SupportCandy plugin through 2.0.0 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension.
We have discovered 16 live websites that are affected by CVE-2019-11223.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 16 live websites (0.80% of Supportcandy install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 0 versions ( less than 0.1% of all versions) |
| 2 websites | |
| 2 websites | |
| 2 websites | |
| 2 websites | |
| 1 websites | |
| 1 websites | |
| 1 websites | |
| 1 websites | |
| 1 websites | |
| 1 websites |
| .com | 5 websites |
| .net | 2 websites |
| .com.au | 1 websites |
| .de | 1 websites |
| .eu | 1 websites |
| .pl | 1 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ***********.com | *,***,*** | ||
| **************.com | *,***,*** | ||
| *********.de | **,***,*** | ||
| *********.ir | **,***,*** | ||
| *****.***.tr | **,***,*** | ||
| *******.eu | **,***,*** | ||
| ****.*************.net | **,***,*** | ||
| ********.com | **,***,*** | ||
| ***************.com | **,***,*** | ||
| ****.***.my | **,***,*** |
FAQ