CVE-2023-0224


GiveWP < 2.24.1 - Unauthenticated SQLi

The GiveWP WordPress plugin before 2.24.1 does not properly escape user input before it reaches SQL queries, which could let unauthenticated attackers perform SQL Injection attacks



We have discovered 2,488 live websites that are affected by CVE-2023-0224.

Contact us to get more info




Affected Software

Product  GiveWP
Category Wordpress Plugins
Vulnerable Versions
  • from 0 before 2.24.1
Total Vulnerable Versions178
Vulnerable Domains2,488 live websites (17.90% of GiveWP install base)


Common Weakness Enumeration


CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2023-0224 and the relative popularity of websites


Details

  • Published - Jan 16, 2024
  • Updated - Jan 16, 2024

Credits

  • dc11 (finder)
  • WPScan (coordinator)





Countries

United States1,139 websites



GB145 websites
Italy144 websites
Germany125 websites
France115 websites
India87 websites
Canada71 websites
Australia64 websites
Spain57 websites
Netherlands28 websites

TLDs

.org1,027 websites
.com630 websites
.it86 websites
.de53 websites
.org.uk45 websites
.net41 websites
.fr39 websites
.ca35 websites
.co.uk32 websites
.eu20 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2023-0224 through included software libraries and plugins.



References


Websites affected by CVE-2023-0224

Top websites that are affected by CVE-2023-0224. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
***.******************.org United States*,***
***.******************.org United States**,***
***.*****************.org United States**,***
*****.org United States**,***
*********.org GB**,***
****************.org Germany**,***
***.*******.org United States**,***
*************.org United States**,***
***.**************.com Australia**,***
***************.no Norway**,***
See full domain list