The 10WebMapBuilder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Plugin Settings Change in versions up to, and including, 1.0.63 due to insufficient input sanitization and output escaping and a lack of capability checks. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 1,981 live websites that are affected by CVE-2020-36853.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 1,981 live websites (100% of Wd Google Maps install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 0 versions ( less than 0.1% of all versions) |
| 415 websites | |
| 239 websites | |
| 160 websites | |
| 118 websites | |
| 97 websites | |
| 75 websites | |
| 66 websites | |
| 52 websites | |
| 47 websites | |
| 40 websites |
| .com | 689 websites |
| .de | 131 websites |
| .it | 84 websites |
| .fr | 80 websites |
| .org | 74 websites |
| .co.uk | 56 websites |
| .nl | 56 websites |
| .pl | 55 websites |
| .ch | 44 websites |
| .net | 43 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| **************.app | **,*** | ||
| ****.*****.edu | ***,*** | ||
| ***.***.uk | ***,*** | ||
| ****.org | ***,*** | ||
| ****************.***.uk | ***,*** | ||
| ********.com | ***,*** | ||
| ******.de | ***,*** | ||
| *********.fr | ***,*** | ||
| ********.com | ***,*** | ||
| ********.com | ***,*** |
FAQ