CVE-2023-1069


Complianz - GDPR/CCPA Cookie Consent < 6.4.2 - Contributor+ Stored XSS

The Complianz WordPress plugin before 6.4.2, Complianz Premium WordPress plugin before 6.4.2 do not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks



We have discovered 37,802 live websites that are affected by CVE-2023-1069.

Contact us to get more info




Affected Software

Product  Complianz
Category Cookie compliance
Vulnerable Versions
  • from 0 before 6.4.2
Total Vulnerable Versions133
Vulnerable Domains37,802 live websites (12.10% of Complianz install base)


Common Weakness Enumeration


CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2023-1069 and the relative popularity of websites


Details

  • Published - Mar 27, 2023
  • Updated - Mar 27, 2023

Credits

  • Erwan LR (WPScan) (finder)
  • WPScan (coordinator)





Countries

United States1,712 websites



Germany12,674 websites
Italy4,300 websites
France4,036 websites
Spain4,027 websites
Czech Republic1,791 websites
Netherlands1,184 websites
Austria1,157 websites
GB919 websites
Slovakia826 websites

TLDs

.de9,958 websites
.com9,533 websites
.it2,932 websites
.fr1,915 websites
.cz1,605 websites
.es1,524 websites
.at1,003 websites
.nl995 websites
.org791 websites
.eu618 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2023-1069 through included software libraries and plugins.



References


Websites affected by CVE-2023-1069

Top websites that are affected by CVE-2023-1069. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
*********.com United States*,***
***********.it Italy**,***
*****.com United States**,***
***.******.com GB**,***
***.******.nl Netherlands**,***
******.**********.fr France**,***
************.com France**,***
***.********.com Germany**,***
***********.com France**,***
************.com United States**,***
See full domain list