CVE-2023-2359

Revolution Slider <= 6.6.12 - Author+ Remote Code Execution

The Slider Revolution WordPress plugin through 6.6.12 does not check for valid image files upon import, leading to an arbitrary file upload which may be escalated to Remote Code Execution in some server configurations.


We have discovered 820,866 live websites that are affected by CVE-2023-2359.

Run a Free Instant Scan




Affected Software

Product  Revslider
Category UI Frameworks
Vulnerable Domains820,866 live websites (60% of Revslider install base)
Vulnerable Versions
  • from 0 through 6.6.12
Vulnerable Versions Count319 versions ( 83% of all versions)


Common Weakness Enumeration

CWE-94 Improper Control of Generation of Code ('Code Injection')



Details

  • Published - Jun 19, 2023
  • Updated - Dec 12, 2024

Credits

  • Marco Frison (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2023-2359
United States194,853 websites



Germany82,499 websites
Italy58,005 websites
France49,414 websites
GB36,086 websites
Spain31,117 websites
Turkey22,956 websites
Netherlands22,615 websites
Poland21,846 websites
Brazil20,415 websites

Website Distribution by TLD

Number of websites using CVE-2023-2359
.com336,279 websites
.de43,977 websites
.it40,847 websites
.org27,546 websites
.co.uk21,244 websites
.nl19,701 websites
.com.br19,577 websites
.fr19,353 websites
.pl16,368 websites
.net15,273 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2023-2359

Top websites that are affected by CVE-2023-2359. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******.com France*,***
***********.eu Cyprus*,***
************.com Singapore*,***
******************.org United States*,***
************.ie United States*,***
**********.org United States*,***
************.net United States*,***
********************.com Cyprus*,***
******************.cat Spain*,***
*****************.com United States*,***
See full domain list

FAQ

CVE-2023-2359 is Improper Control of Generation of Code ('Code Injection') in Revslider
A total of 820,866 websites have been identified as vulnerable to CVE-2023-2359, based on global website indexing conducted by WebTechSurvey.
The Revslider is affected by the CVE-2023-2359 vulnerability.
Revslider versions up to and including 6.6.12 are vulnerable to CVE-2023-2359.