CVE-2023-1324


Easy Forms for MailChimp < 6.8.8 - Reflected XSS

The Easy Forms for Mailchimp WordPress plugin before 6.8.8 does not sanitise and escape some parameters before outputting them back in the response, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin



We have discovered 1,621 live websites that are affected by CVE-2023-1324.

Contact us to get more info




Affected Software

Product  Easy Forms for Mailchimp
Category Wordpress Plugins
Vulnerable Versions
  • from 0 before 6.8.8
Total Vulnerable Versions64
Vulnerable Domains1,621 live websites (32.67% of Easy Forms for Mailchimp install base)


Common Weakness Enumeration


CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2023-1324 and the relative popularity of websites


Details

  • Published - Apr 24, 2023
  • Updated - Apr 24, 2023

Credits

  • Erwan LR (WPScan) (finder)
  • WPScan (coordinator)





Countries

United States546 websites



Italy159 websites
GB108 websites
Germany84 websites
France69 websites
Netherlands59 websites
Spain55 websites
Australia54 websites
Canada52 websites
Brazil28 websites

TLDs

.com774 websites
.org121 websites
.it91 websites
.co.uk43 websites
.nl38 websites
.de36 websites
.com.au35 websites
.net29 websites
.fr29 websites
.eu21 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2023-1324 through included software libraries and plugins.



References


Websites affected by CVE-2023-1324

Top websites that are affected by CVE-2023-1324. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
************.com United States**,***
*************.com United States**,***
*********.net United States***,***
***.******************.com United States***,***
************.**.uk GB***,***
*****.tv Netherlands***,***
***.**********.com United States***,***
****.com United States***,***
****.*******.com Denmark***,***
********.*******.com United States***,***
See full domain list