CVE-2023-1420


Ajax Search Lite < 4.11.1, Pro < 4.26.2 - Reflected Cross-Site Scripting

The Ajax Search Lite WordPress plugin before 4.11.1, Ajax Search Pro WordPress plugin before 4.26.2 does not sanitise and escape a parameter before outputting it back in a response of an AJAX action, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin



We have discovered 837 live websites that are affected by CVE-2023-1420.

Contact us to get more info




Affected Software

Product  Ajax Search Lite
Category Wordpress Plugins
Vulnerable Versions
  • from 0 before 4.11.1
Total Vulnerable Versions47
Vulnerable Domains837 live websites (96.54% of Ajax Search Lite install base)


Common Weakness Enumeration


CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2023-1420 and the relative popularity of websites


Details

  • Published - Apr 24, 2023
  • Updated - Apr 24, 2023

Credits

  • Erwan LR (WPScan) (finder)
  • WPScan (coordinator)





Countries

United States176 websites



Russia89 websites
Germany65 websites
France65 websites
Italy47 websites
GB36 websites
Spain30 websites
Poland24 websites
Brazil20 websites
Netherlands19 websites

TLDs

.com282 websites
.ru82 websites
.org48 websites
.de40 websites
.fr35 websites
.it21 websites
.pl20 websites
.co.uk15 websites
.es14 websites
.ca13 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2023-1420 through included software libraries and plugins.



References


Websites affected by CVE-2023-1420

Top websites that are affected by CVE-2023-1420. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
***.******.at Austria*,***
*********.com Netherlands**,***
**********.com United States**,***
***.***.**.ca Canada**,***
**********.com Canada**,***
***.***********.com Mexico**,***
*************.eu Germany**,***
******.ru Russia**,***
***********.com United States**,***
***.*****************.org Italy***,***
See full domain list