CVE-2023-2168

TaxoPress <= 3.6.4 - Authenticated (Editor+) Stored Cross-Site Scripting

The TaxoPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Suggest Terms Title field in versions up to, and including, 3.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with Editor+ permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.


We have discovered 1,216 live websites that are affected by CVE-2023-2168.

Run a Free Instant Scan




Affected Software

Product  Simple Tags
Category Wordpress Plugins
Vulnerable Domains1,216 live websites (9.48% of Simple Tags install base)
Vulnerable Versions
  • from 0 through 3.6.4
Vulnerable Versions Count51 versions ( 54% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Apr 19, 2023
  • Updated - Apr 8, 2026

Credits

  • Ivan Kuzymchak (finder)

Website Distribution by Country

Number of websites using CVE-2023-2168
United States212 websites



Russia216 websites
Japan182 websites
Italy131 websites
Germany111 websites
France63 websites
Turkey28 websites
Poland23 websites
Spain22 websites

Website Distribution by TLD

Number of websites using CVE-2023-2168
.com488 websites
.ru143 websites
.net91 websites
.it84 websites
.de58 websites
.org42 websites
.jp37 websites
.info28 websites
.pl19 websites
.fr17 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2023-2168

Top websites that are affected by CVE-2023-2168. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**************.com United States**,***
*********************.com United States**,***
***********.com United States**,***
*************.com United States**,***
****************.com Japan***,***
*******.org Spain***,***
****.**********.net United States***,***
**********.net United States***,***
****.********.us United States***,***
********.com United States***,***
See full domain list

FAQ

CVE-2023-2168 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Simple Tags
A total of 1,216 websites have been identified as vulnerable to CVE-2023-2168, based on global website indexing conducted by WebTechSurvey.
The Simple Tags is affected by the CVE-2023-2168 vulnerability.
Simple Tags versions up to and including 3.6.4 are vulnerable to CVE-2023-2168.