CVE-2022-4057


Autoptimize < 3.1.0 - Sensitive Data Disclosure

The Autoptimize WordPress plugin before 3.1.0 uses an easily guessable path to store plugin's exported settings and logs.



We have discovered 7,643 live websites that are affected by CVE-2022-4057.

Contact us to get more info




Affected Software

Product  Autoptimize
Category Widgets
Vulnerable Versions
  • from 0 before 3.1
Total Vulnerable Versions1,307
Vulnerable Domains7,643 live websites (10.29% of Autoptimize install base)


Common Weakness Enumeration


CWE-425 Direct Request ('Forced Browsing')



Details

  • Published - Jan 2, 2023
  • Updated - Jul 19, 2023

Credits

  • Raad Haddad of Cloudyrion GmbH (finder)
  • WPScan (coordinator)





Countries

United States1,961 websites



Germany902 websites
Russia459 websites
Japan448 websites
Poland364 websites
GB362 websites
France340 websites
Canada283 websites
Italy237 websites
Spain234 websites

TLDs

.com3,135 websites
.de551 websites
.ru363 websites
.org363 websites
.pl244 websites
.net206 websites
.co.uk188 websites
.it165 websites
.fr138 websites
.jp136 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


References


Websites affected by CVE-2022-4057

Top websites that are affected by CVE-2022-4057. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.**********.com United States***
************.com United States*,***
***.******.com United States*,***
***.****.de Germany*,***
**************.de Germany**,***
***.**********.com United States**,***
***.***********.org United States**,***
*********.com United States**,***
******.com India**,***
***.***********.com United States**,***
See full domain list