CVE-2022-4699


MediaElement.js – HTML5 Video & Audio Player <= 4.2.8 - Contributor+ Stored XSS via Shortcode

The MediaElement.js WordPress plugin through 4.2.8 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high-privilege users such as admins.



We have discovered 21,547 live websites that are affected by CVE-2022-4699.

Contact us to get more info




Affected Software

Product  MediaElement.js
Category Video Players
Vulnerable Versions
  • from 0 through 4.2.8
Total Vulnerable Versions153
Vulnerable Domains21,547 live websites (9.50% of MediaElement.js install base)


Common Weakness Enumeration


CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2022-4699 and the relative popularity of websites


Details

  • Published - Jan 30, 2023

Credits

  • Lana Codes (finder)
  • WPScan (coordinator)





Countries

United States3,109 websites



Germany9,188 websites
France1,304 websites
Austria890 websites
Switzerland876 websites
Italy813 websites
GB486 websites
Spain434 websites
Poland383 websites
Netherlands349 websites

TLDs

.de7,431 websites
.com5,778 websites
.org850 websites
.at779 websites
.ch759 websites
.fr562 websites
.net496 websites
.it457 websites
.eu342 websites
.pl277 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2022-4699 through included software libraries and plugins.



References


Websites affected by CVE-2022-4699

Top websites that are affected by CVE-2022-4699. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
***.***.cl Chile**,***
*****************************.lt Lithuania**,***
***************.com United States**,***
**********.***.tw Taiwan**,***
***.********.***.cn China**,***
***********************.****.br Brazil**,***
***********.com United States**,***
***.******.org Austria**,***
***.***************.nl Netherlands**,***
*******.fr France**,***
See full domain list