CVE-2023-23668


WordPress GiveWP Plugin <= 2.25.1 is vulnerable to Cross Site Scripting (XSS)

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in GiveWP plugin <= 2.25.1 versions.



We have discovered 2,748 live websites that are affected by CVE-2023-23668.

Contact us to get more info




Affected Software

Product  GiveWP
Category Wordpress Plugins
Vulnerable Versions
  • from 0 through 2.25.1
Total Vulnerable Versions178
Vulnerable Domains2,748 live websites (19.78% of GiveWP install base)


Common Weakness Enumeration


CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2023-23668 and the relative popularity of websites


Details

  • Published - May 8, 2023
  • Updated - May 8, 2023

Credits

  • Rafshanzani Suhada (Patchstack Alliance) (finder)





Countries

United States1,260 websites



GB166 websites
Italy155 websites
Germany145 websites
France127 websites
India92 websites
Canada82 websites
Spain67 websites
Australia67 websites
Netherlands32 websites

TLDs

.org1,156 websites
.com683 websites
.it94 websites
.de64 websites
.org.uk51 websites
.fr45 websites
.net43 websites
.ca39 websites
.co.uk36 websites
.eu21 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2023-23668 through included software libraries and plugins.



References


Websites affected by CVE-2023-23668

Top websites that are affected by CVE-2023-23668. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
***.******************.org United States*,***
***.******************.org United States**,***
***.*****************.org United States**,***
*****.org United States**,***
********.org GB**,***
*********.org GB**,***
****************.org Germany**,***
***.*******.org United States**,***
*************.org United States**,***
***.**************.com Australia**,***
See full domain list