CVE-2023-0380
Easy Digital Downloads < 3.1.0.5 - Contributor+ Stored XSSThe Easy Digital Downloads WordPress plugin before 3.1.0.5 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
We have discovered 5,854 live websites that are affected by CVE-2023-0380.
Contact us to get more info
Common Weakness Enumeration
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Distribution by Website Rank
The diagram provides a graphic representation of the correlation between the occurrence of CVE-2023-0380 and the relative popularity of websites