The CC Child Pages WordPress plugin before 1.43 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
We have discovered 609 live websites that are affected by CVE-2022-4776.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 609 live websites (14% of Cc Child Pages install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 13 versions ( 93% of all versions) |
| 133 websites | |
| 108 websites | |
| 44 websites | |
| 34 websites | |
| 31 websites | |
| 30 websites | |
| 27 websites | |
| 26 websites | |
| 16 websites | |
| 13 websites |
| .com | 202 websites |
| .jp | 32 websites |
| .org | 31 websites |
| .de | 31 websites |
| .net | 26 websites |
| .ru | 21 websites |
| .co.jp | 21 websites |
| .pl | 20 websites |
| .it | 19 websites |
| .co.uk | 10 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *********.com | ***,*** | ||
| *******.com | ***,*** | ||
| ****.***.br | ***,*** | ||
| *******************.com | ***,*** | ||
| ****.**.jp | ***,*** | ||
| ******.mt | *,***,*** | ||
| ******************.com | *,***,*** | ||
| *****.org | *,***,*** | ||
| ************.com | *,***,*** | ||
| *********.**.jp | *,***,*** |
FAQ