CVE-2023-2010

Forminator < 1.24.1 - Unauthenticated Race Condition on poll vote

The Forminator WordPress plugin before 1.24.1 does not use an atomic operation to check whether a user has already voted, and then update that information. This leads to a Race Condition that may allow a single user to vote multiple times on a poll.


We have discovered 4,669 live websites that are affected by CVE-2023-2010.

Run a Free Instant Scan




Affected Software

Product  Forminator
Category Wordpress Plugins
Vulnerable Domains4,669 live websites (6.79% of Forminator install base)
Vulnerable Versions
  • from 0 through 1.24.1
Vulnerable Versions Count77 versions ( 55% of all versions)


Common Weakness Enumeration

CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')



Details

  • Published - Jul 4, 2023
  • Updated - Nov 22, 2024

Credits

  • Amirmohammad vakili (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2023-2010
United States1,345 websites



France334 websites
Germany328 websites
GB324 websites
Canada244 websites
Italy194 websites
Netherlands133 websites
Poland123 websites
India116 websites
Spain105 websites

Website Distribution by TLD

Number of websites using CVE-2023-2010
.com2,049 websites
.co.uk199 websites
.org176 websites
.de154 websites
.fr147 websites
.it128 websites
.nl120 websites
.ca112 websites
.com.au101 websites
.pl94 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2023-2010

Top websites that are affected by CVE-2023-2010. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.com United States*,***
*****.com Canada**,***
************.com United States**,***
**********.com United States***,***
***********.de Germany***,***
*********.***.br Brazil***,***
************.io Germany***,***
*********.co United States***,***
***************.de Germany***,***
**********.com United States***,***
See full domain list

FAQ

CVE-2023-2010 is Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in Forminator
A total of 4,669 websites have been identified as vulnerable to CVE-2023-2010, based on global website indexing conducted by WebTechSurvey.
The Forminator is affected by the CVE-2023-2010 vulnerability.
Forminator versions up to 1.24.1 are vulnerable to CVE-2023-2010.
CVE-2023-2010 is resolved in version 1.24.1 of Forminator.