CVE-2022-4448


GiveWP < 2.24.0 - Contributor+ Stored XSS

The GiveWP WordPress plugin before 2.24.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks



We have discovered 2,476 live websites that are affected by CVE-2022-4448.

Contact us to get more info




Affected Software

Product  GiveWP
Category Wordpress Plugins
Vulnerable Versions
  • from 0 before 2.24
Total Vulnerable Versions178
Vulnerable Domains2,476 live websites (17.82% of GiveWP install base)


Common Weakness Enumeration


CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2022-4448 and the relative popularity of websites


Details

  • Published - Feb 13, 2023

Credits

  • Lana Codes (finder)
  • WPScan (coordinator)





Countries

United States1,134 websites



GB145 websites
Italy143 websites
Germany125 websites
France114 websites
India86 websites
Canada70 websites
Australia64 websites
Spain57 websites
Netherlands28 websites

TLDs

.org1,021 websites
.com629 websites
.it86 websites
.de53 websites
.org.uk45 websites
.net41 websites
.fr38 websites
.ca34 websites
.co.uk32 websites
.eu20 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2022-4448 through included software libraries and plugins.



References


Websites affected by CVE-2022-4448

Top websites that are affected by CVE-2022-4448. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
***.******************.org United States*,***
***.******************.org United States**,***
***.*****************.org United States**,***
*****.org United States**,***
*********.org GB**,***
****************.org Germany**,***
***.*******.org United States**,***
*************.org United States**,***
***.**************.com Australia**,***
***************.no Norway**,***
See full domain list