CVE-2022-4571


Seriously Simple Podcasting < 2.19.1 - Contributor+ Stored XSS

The Seriously Simple Podcasting WordPress plugin before 2.19.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.



We have discovered 2,074 live websites that are affected by CVE-2022-4571.

Contact us to get more info




Affected Software

Product  Seriously Simple Podcasting
Category Wordpress Plugins
Vulnerable Versions
  • from 0 before 2.19.1
Total Vulnerable Versions136
Vulnerable Domains2,074 live websites (25.31% of Seriously Simple Podcasting install base)


Common Weakness Enumeration


CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2022-4571 and the relative popularity of websites


Details

  • Published - Jan 16, 2023

Credits

  • Lana Codes (finder)
  • WPScan (coordinator)





Countries

United States946 websites



Germany209 websites
France116 websites
GB75 websites
Canada60 websites
Italy59 websites
Poland50 websites
Japan49 websites
Brazil45 websites
Australia30 websites

TLDs

.com1,075 websites
.org174 websites
.de119 websites
.net77 websites
.pl39 websites
.fr37 websites
.com.br37 websites
.it36 websites
.ca35 websites
.co.uk35 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2022-4571 through included software libraries and plugins.



References


Websites affected by CVE-2022-4571

Top websites that are affected by CVE-2022-4571. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
*********.org United States*
***.**********.com United States*,***
***.********.org United States**,***
***.************.ca Canada**,***
***.**.edu United States**,***
***.********.com Japan**,***
************.com United States***,***
*****************.com GB***,***
*************.de Germany***,***
*********.com United States***,***
See full domain list