CVE-2023-0082


ExactMetrics < 7.12.1 - Contributor+ Stored XSS

The ExactMetrics WordPress plugin before 7.12.1 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.



We have discovered 80,290 live websites that are affected by CVE-2023-0082.

Contact us to get more info




Affected Software

Product  ExactMetrics
Category Analytics
Vulnerable Versions
  • from 0 before 7.12.1
Total Vulnerable Versions86
Vulnerable Domains80,290 live websites (32.00% of ExactMetrics install base)


Common Weakness Enumeration


CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2023-0082 and the relative popularity of websites


Details

  • Published - Feb 6, 2023

Credits

  • Lana Codes (finder)
  • WPScan (coordinator)





Countries

United States22,266 websites



France7,260 websites
Germany5,031 websites
GB4,311 websites
Italy4,203 websites
Netherlands3,662 websites
Japan3,404 websites
Brazil2,592 websites
Spain2,550 websites
Poland2,004 websites

TLDs

.com35,493 websites
.org3,396 websites
.fr3,272 websites
.nl3,011 websites
.it2,757 websites
.de2,704 websites
.co.uk2,576 websites
.com.br2,230 websites
.net1,886 websites
.pl1,513 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2023-0082 through included software libraries and plugins.



References


Websites affected by CVE-2023-0082

Top websites that are affected by CVE-2023-0082. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
*********.com United States*,***
*********.com United States*,***
*********.com United States*,***
*********.com United States*,***
**********.com United States*,***
*****************.****************.com United States*,***
*********.com United States*,***
*********.com United States*,***
*****************.*********.com United States*,***
***.***************.com South Africa*,***
See full domain list