CVE-2022-4562


Meks Flexible Shortcodes < 1.3.5 - Contributor+ Stored XSS

The Meks Flexible Shortcodes WordPress plugin before 1.3.5 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.



We have discovered 476 live websites that are affected by CVE-2022-4562.

Contact us to get more info




Affected Software

Product  Meks Flexible Shortcodes
Category Wordpress Plugins
Vulnerable Versions
  • from 0 before 1.3.5
Total Vulnerable Versions14
Vulnerable Domains476 live websites (24.92% of Meks Flexible Shortcodes install base)


Common Weakness Enumeration


CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2022-4562 and the relative popularity of websites


Details

  • Published - Feb 13, 2023

Credits

  • Lana Codes (finder)
  • WPScan (coordinator)





Countries

United States153 websites



Germany35 websites
France29 websites
Italy24 websites
GB21 websites
Russia19 websites
Poland17 websites
Canada13 websites
Brazil12 websites
Spain12 websites

TLDs

.com210 websites
.org35 websites
.de17 websites
.net14 websites
.it14 websites
.pl13 websites
.fr11 websites
.ru11 websites
.nl7 websites
.ca6 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2022-4562 through included software libraries and plugins.



References


Websites affected by CVE-2022-4562

Top websites that are affected by CVE-2022-4562. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
***.*************.de Germany**,***
********.co Germany**,***
***.**************.com Hong Kong**,***
*********.com United States**,***
***.**************.com United States**,***
***.*******************.com Germany**,***
********.com Ukraine***,***
***.************.com United States***,***
*******.com United States***,***
***************.com GB***,***
See full domain list