CVE-2022-38456


WordPress Ajax Search Lite Plugin <= 4.10.3 is vulnerable to Sensitive Data Exposure

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ernest Marcinko Ajax Search Lite plugin <= 4.10.3 versions.



We have discovered 837 live websites that are affected by CVE-2022-38456.

Contact us to get more info




Affected Software

Product  Ajax Search Lite
Category Wordpress Plugins
Vulnerable Versions
  • from 0 through 4.10.3
Total Vulnerable Versions47
Vulnerable Domains837 live websites (96.54% of Ajax Search Lite install base)


Common Weakness Enumeration


CWE-200 Exposure of Sensitive Information to an Unauthorized Actor


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2022-38456 and the relative popularity of websites


Details

  • Published - Mar 15, 2023
  • Updated - Mar 15, 2023

Credits

  • Lana Codes (Patchstack Alliance) (finder)





Countries

United States176 websites



Russia89 websites
Germany65 websites
France65 websites
Italy47 websites
GB36 websites
Spain30 websites
Poland24 websites
Brazil20 websites
Netherlands19 websites

TLDs

.com282 websites
.ru82 websites
.org48 websites
.de40 websites
.fr35 websites
.it21 websites
.pl20 websites
.co.uk15 websites
.es14 websites
.ca13 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2022-38456 through included software libraries and plugins.



References


Websites affected by CVE-2022-38456

Top websites that are affected by CVE-2022-38456. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
***.******.at Austria*,***
*********.com Netherlands**,***
**********.com United States**,***
***.***.**.ca Canada**,***
**********.com Canada**,***
***.***********.com Mexico**,***
*************.eu Germany**,***
******.ru Russia**,***
***********.com United States**,***
***.*****************.org Italy***,***
See full domain list