CVE-2023-2359

Revolution Slider <= 6.6.12 - Author+ Remote Code Execution

The Slider Revolution WordPress plugin through 6.6.12 does not check for valid image files upon import, leading to an arbitrary file upload which may be escalated to Remote Code Execution in some server configurations.


We have discovered 1,139,664 live websites that are affected by CVE-2023-2359.

Test my site




Affected Software

Product  Revslider
Category UI Frameworks
Vulnerable Domains1,139,664 live websites (68.68% of Revslider install base)
Vulnerable Versions
  • from 0 through 6.6.12
Vulnerable Versions Count439 versions ( 87.98% of all versions)


Common Weakness Enumeration

CWE-94 Improper Control of Generation of Code ('Code Injection')



Details

  • Published - Jun 19, 2023
  • Updated - Dec 12, 2024

Credits

  • Marco Frison (finder)
  • WPScan (coordinator)

CVE-2023-2359 usage by Country

United States357,766 websites



Germany138,112 websites
France78,924 websites
GB43,954 websites
Italy43,325 websites
Spain36,119 websites
Netherlands29,608 websites
Poland29,554 websites
Turkey27,467 websites
Russia25,103 websites

CVE-2023-2359 usage by TLD

.com478,094 websites
.de59,914 websites
.org38,935 websites
.it37,517 websites
.co.uk31,847 websites
.com.br28,333 websites
.nl27,798 websites
.fr26,999 websites
.pl23,449 websites
.com.au22,247 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2023-2359

Top websites that are affected by CVE-2023-2359. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******.com United States*,***
***********.eu Germany*,***
************.com Singapore*,***
******************.org United States*,***
****.int Canada*,***
************.ie United States*,***
**********.org United States*,***
************.net United States*,***
***********************.com United States*,***
******************.cat Spain*,***
See full domain list

FAQ

CVE-2023-2359 is Improper Control of Generation of Code ('Code Injection') in Revslider
A total of 1,139,664 websites have been identified as vulnerable to CVE-2023-2359, discovered through global website indexing conducted by WebTechSurvey.
Revslider is susceptible to CVE-2023-2359 vulnerability.
Revslider versions before, and including, 6.6.12 are vulnerable to CVE-2023-2359.