CVE-2023-23725

WordPress Shortcodes by Angie Makes plugin <= 3.46 - Broken Access Control vulnerability

Missing Authorization vulnerability in Chris Baldelomar Shortcodes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Shortcodes: from n/a through 3.46.


We have discovered 8,971 live websites that are affected by CVE-2023-23725.

Test my site




Affected Software

Product  Shortcodes
Category Wordpress Plugins
Vulnerable Domains8,971 live websites (99.97% of Shortcodes install base)
Vulnerable Versions
  • from 0 through 3.46
Vulnerable Versions Count78 versions ( 97.50% of all versions)


Common Weakness Enumeration

CWE-862 Missing Authorization



Details

  • Published - Dec 9, 2024
  • Updated - Dec 9, 2024

Credits

  • István Márton (Patchstack Alliance) (finder)

CVE-2023-23725 usage by Country

United States1,543 websites



Japan5,158 websites
Germany532 websites
France199 websites
Poland102 websites
Netherlands101 websites
GB97 websites
Italy81 websites
Switzerland72 websites

CVE-2023-23725 usage by TLD

.com4,459 websites
.jp1,026 websites
.net586 websites
.co.jp566 websites
.de338 websites
.org280 websites
.info109 websites
.pl106 websites
.nl82 websites
.fr79 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2023-23725

Top websites that are affected by CVE-2023-23725. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.com Bulgaria**,***
**********.com United States**,***
*******.*******.pl Poland**,***
***.com United States**,***
************.com United States***,***
***********.com United States***,***
*************.**********.com United States***,***
***********.it Italy***,***
**********.org United States***,***
**************.com United States***,***
See full domain list

FAQ

CVE-2023-23725 is Missing Authorization in Shortcodes
A total of 8,971 websites have been identified as vulnerable to CVE-2023-23725, discovered through global website indexing conducted by WebTechSurvey.
Shortcodes is susceptible to CVE-2023-23725 vulnerability.
Shortcodes versions before, and including, 3.46 are vulnerable to CVE-2023-23725.