The Forminator WordPress plugin before 1.24.1 does not use an atomic operation to check whether a user has already voted, and then update that information. This leads to a Race Condition that may allow a single user to vote multiple times on a poll.
We have discovered 4,669 live websites that are affected by CVE-2023-2010.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 4,669 live websites (6.79% of Forminator install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 77 versions ( 55% of all versions) |
| 1,345 websites | |
| 334 websites | |
| 328 websites | |
| 324 websites | |
| 244 websites | |
| 194 websites | |
| 133 websites | |
| 123 websites | |
| 116 websites | |
| 105 websites |
| .com | 2,049 websites |
| .co.uk | 199 websites |
| .org | 176 websites |
| .de | 154 websites |
| .fr | 147 websites |
| .it | 128 websites |
| .nl | 120 websites |
| .ca | 112 websites |
| .com.au | 101 websites |
| .pl | 94 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ********.com | *,*** | ||
| *****.com | **,*** | ||
| ************.com | **,*** | ||
| **********.com | ***,*** | ||
| ***********.de | ***,*** | ||
| *********.***.br | ***,*** | ||
| ************.io | ***,*** | ||
| *********.co | ***,*** | ||
| ***************.de | ***,*** | ||
| **********.com | ***,*** |
FAQ