CVE-2023-0380


Easy Digital Downloads < 3.1.0.5 - Contributor+ Stored XSS

The Easy Digital Downloads WordPress plugin before 3.1.0.5 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.



We have discovered 5,854 live websites that are affected by CVE-2023-0380.

Contact us to get more info




Affected Software

Product  Easy Digital Downloads
Category Ecommerce
Vulnerable Versions
  • from 0 before 3.1.0.5
Total Vulnerable Versions168
Vulnerable Domains5,854 live websites (31.31% of Easy Digital Downloads install base)


Common Weakness Enumeration


CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2023-0380 and the relative popularity of websites


Details

  • Published - Feb 21, 2023
  • Updated - Feb 21, 2023

Credits

  • Lana Codes (finder)
  • WPScan (coordinator)





Countries

United States2,419 websites



Iran541 websites
Germany390 websites
GB297 websites
France267 websites
Italy230 websites
Poland161 websites
Japan150 websites
Canada115 websites
Spain102 websites

TLDs

.com3,313 websites
.org319 websites
.net203 websites
.de143 websites
.it137 websites
.co.uk129 websites
.pl128 websites
.fr70 websites
.ru65 websites
.com.au59 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2023-0380 through included software libraries and plugins.



References


Websites affected by CVE-2023-0380

Top websites that are affected by CVE-2023-0380. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
***.***************.eu Romania*,***
***.**********.com United States*,***
***.*************.com United States*,***
*********.com United States*,***
********.com United States*,***
***.****************.com United States*,***
**************.net United States**,***
***.***********.com United States**,***
***.***********.com Australia**,***
***.*************.com United States**,***
See full domain list