CVE-2023-23800

WordPress Shortcodes Ultimate Plugin <= 5.12.6 is vulnerable to Server Side Request Forgery (SSRF)

Server-Side Request Forgery (SSRF) vulnerability in Vova Anokhin WP Shortcodes Plugin — Shortcodes Ultimate.This issue affects WP Shortcodes Plugin — Shortcodes Ultimate: from n/a through 5.12.6.


We have discovered 23,643 live websites that are affected by CVE-2023-23800.

Test my site




Affected Software

Product  Shortcodes Ultimate
Category Widgets
Vulnerable Domains23,643 live websites (31.86% of Shortcodes Ultimate install base)
Vulnerable Versions
  • from 0 through 5.12.6
Vulnerable Versions Count107 versions ( 74.83% of all versions)


Common Weakness Enumeration

CWE-918 Server-Side Request Forgery (SSRF)



Details

  • Published - Nov 13, 2023
  • Updated - Aug 28, 2024

Credits

  • Rafie Muhammad (Patchstack) (finder)

CVE-2023-23800 usage by Country

United States4,834 websites



Japan5,305 websites
Russia2,439 websites
Germany2,274 websites
France1,203 websites
Poland799 websites
GB525 websites
Italy473 websites
Spain468 websites
Canada400 websites

CVE-2023-23800 usage by TLD

.com8,917 websites
.ru2,036 websites
.de1,311 websites
.org1,293 websites
.jp1,087 websites
.net942 websites
.pl640 websites
.co.jp559 websites
.fr457 websites
.it352 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2023-23800

Top websites that are affected by CVE-2023-23800. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***********.net United States**,***
******.com United States**,***
********.com Bulgaria**,***
*****************.com United States**,***
******.pl Poland**,***
************.fr France**,***
****.org United States**,***
***.org United States**,***
************************.gov United States***,***
*******.com United States***,***
See full domain list

FAQ

CVE-2023-23800 is Server-Side Request Forgery (SSRF) in Shortcodes Ultimate
A total of 23,643 websites have been identified as vulnerable to CVE-2023-23800, discovered through global website indexing conducted by WebTechSurvey.
Shortcodes Ultimate is susceptible to CVE-2023-23800 vulnerability.
Shortcodes Ultimate versions before, and including, 5.12.6 are vulnerable to CVE-2023-23800.