CVE-2023-1325


Easy Forms for MailChimp < 6.8.7 - Contributor+ Stored XSS

The Easy Forms for Mailchimp WordPress plugin before 6.8.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks



We have discovered 1,609 live websites that are affected by CVE-2023-1325.

Contact us to get more info




Affected Software

Product  Easy Forms for Mailchimp
Category Wordpress Plugins
Vulnerable Versions
  • from 0 before 6.8.7
Total Vulnerable Versions64
Vulnerable Domains1,609 live websites (32.43% of Easy Forms for Mailchimp install base)


Common Weakness Enumeration


CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2023-1325 and the relative popularity of websites


Details

  • Published - Apr 17, 2023
  • Updated - Apr 17, 2023

Credits

  • Erwan LR (WPScan) (finder)
  • WPScan (coordinator)





Countries

United States542 websites



Italy158 websites
GB107 websites
Germany83 websites
France68 websites
Netherlands59 websites
Spain54 websites
Australia53 websites
Canada51 websites
Brazil28 websites

TLDs

.com768 websites
.org120 websites
.it91 websites
.co.uk42 websites
.nl38 websites
.de35 websites
.com.au34 websites
.net29 websites
.fr29 websites
.eu21 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2023-1325 through included software libraries and plugins.



References


Websites affected by CVE-2023-1325

Top websites that are affected by CVE-2023-1325. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
************.com United States**,***
*************.com United States**,***
*********.net United States***,***
***.******************.com United States***,***
************.**.uk GB***,***
*****.tv Netherlands***,***
***.**********.com United States***,***
****.com United States***,***
****.*******.com Denmark***,***
********.*******.com United States***,***
See full domain list