CVE-2022-43490


WordPress Stream Plugin <= 3.9.2 is vulnerable to Cross Site Request Forgery (CSRF)

Cross-Site Request Forgery (CSRF) vulnerability in XWP Stream plugin <= 3.9.2 versions.



We have discovered 7,921 live websites that are affected by CVE-2022-43490.

Contact us to get more info




Affected Software

Product  Stream
Category Wordpress Plugins
Vulnerable Versions
  • from 0 through 3.9.2
Total Vulnerable Versions40
Vulnerable Domains7,921 live websites (18.42% of Stream install base)


Common Weakness Enumeration


CWE-352 Cross-Site Request Forgery (CSRF)


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2022-43490 and the relative popularity of websites


Details

  • Published - May 25, 2023
  • Updated - May 25, 2023

Credits

  • Lucio Sá (Patchstack Alliance) (finder)





Countries

United States4,458 websites



Australia482 websites
GB453 websites
Canada411 websites
Italy259 websites
Germany213 websites
Netherlands182 websites
Spain167 websites
Russia148 websites
France89 websites

TLDs

.com4,610 websites
.org419 websites
.com.au371 websites
.co.uk260 websites
.it207 websites
.net187 websites
.ca182 websites
.nl151 websites
.de139 websites
.ru118 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2022-43490 through included software libraries and plugins.



References


Websites affected by CVE-2022-43490

Top websites that are affected by CVE-2022-43490. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
*****.*********.org United States***
***.******.com United States*,***
***.**************.org United States**,***
***.*******.com United States**,***
***.*****.com United States**,***
***.******.com United States**,***
***.***********.com United States**,***
******.com Singapore**,***
*************.com United States**,***
***.*****.***.au Australia**,***
See full domain list