CVE-2022-45363


WordPress Betheme premium theme <= 26.6.1 - Auth. Stored Cross-Site Scripting (XSS) vulnerability

Auth. (subscriber+) Stored Cross-Site Scripting (XSS) in Muffingroup Betheme theme <= 26.6.1 on WordPress.



We have discovered 7,398 live websites that are affected by CVE-2022-45363.

Contact us to get more info




Affected Software

Product  BeTheme
Category Wordpress Themes
Vulnerable Versions
  • from 0 through 26.6.1
Total Vulnerable Versions512
Vulnerable Domains7,398 live websites (55.27% of BeTheme install base)


Common Weakness Enumeration


CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2022-45363 and the relative popularity of websites


Details

  • Published - Nov 22, 2022
  • Updated - Nov 22, 2022

Credits

  • Dave Jong (Patchstack) (finder)





Countries

United States1,750 websites



Germany1,004 websites
France546 websites
Italy439 websites
Spain300 websites
GB280 websites
Netherlands242 websites
Brazil233 websites
Poland233 websites
Canada164 websites

TLDs

.com2,692 websites
.de683 websites
.org519 websites
.it274 websites
.fr251 websites
.nl190 websites
.com.br178 websites
.pl177 websites
.net163 websites
.co.uk126 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2022-45363 through included software libraries and plugins.



References


Websites affected by CVE-2022-45363

Top websites that are affected by CVE-2022-45363. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
***.*********.nl Netherlands*,***
***.*************.com United States**,***
*******.org Spain**,***
***.buzz United States**,***
*****************.com United States**,***
***.******.fr France**,***
***.****************************.com United States**,***
**********.com United States**,***
**********.com United States**,***
*************.com United States**,***
See full domain list