CVE-2022-43450


WordPress Stream Plugin <= 3.9.2 is vulnerable to Insecure Direct Object References (IDOR)

Authorization Bypass Through User-Controlled Key vulnerability in XWP Stream.This issue affects Stream: from n/a through 3.9.2.



We have discovered 7,921 live websites that are affected by CVE-2022-43450.

Contact us to get more info




Affected Software

Product  Stream
Category Wordpress Plugins
Vulnerable Versions
  • from 0 through 3.9.2
Total Vulnerable Versions40
Vulnerable Domains7,921 live websites (18.42% of Stream install base)


Common Weakness Enumeration


CWE-639 Authorization Bypass Through User-Controlled Key


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2022-43450 and the relative popularity of websites


Details

  • Published - Dec 19, 2023
  • Updated - Dec 19, 2023

Credits

  • Lucio Sá (Patchstack Alliance) (finder)





Countries

United States4,458 websites



Australia482 websites
GB453 websites
Canada411 websites
Italy259 websites
Germany213 websites
Netherlands182 websites
Spain167 websites
Russia148 websites
France89 websites

TLDs

.com4,610 websites
.org419 websites
.com.au371 websites
.co.uk260 websites
.it207 websites
.net187 websites
.ca182 websites
.nl151 websites
.de139 websites
.ru118 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2022-43450 through included software libraries and plugins.



References


Websites affected by CVE-2022-43450

Top websites that are affected by CVE-2022-43450. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
*****.*********.org United States***
***.******.com United States*,***
***.**************.org United States**,***
***.*******.com United States**,***
***.*****.com United States**,***
***.******.com United States**,***
***.***********.com United States**,***
******.com Singapore**,***
*************.com United States**,***
***.*****.***.au Australia**,***
See full domain list