CVE-2023-23880


WordPress ExactMetrics Plugin <= 7.14.1 is vulnerable to Cross Site Scripting (XSS)

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in ExactMetrics plugin <= 7.14.1 versions.



We have discovered 91,444 live websites that are affected by CVE-2023-23880.

Contact us to get more info




Affected Software

Product  ExactMetrics
Category Analytics
Vulnerable Versions
  • from 0 through 7.14.1
Total Vulnerable Versions86
Vulnerable Domains91,444 live websites (36.45% of ExactMetrics install base)


Common Weakness Enumeration


CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2023-23880 and the relative popularity of websites


Details

  • Published - Aug 8, 2023
  • Updated - Aug 8, 2023

Credits

  • Rafie Muhammad (Patchstack) (finder)





Countries

United States25,536 websites



France8,285 websites
Germany5,823 websites
GB4,928 websites
Italy4,678 websites
Netherlands4,302 websites
Japan3,721 websites
Brazil2,914 websites
Spain2,900 websites
Canada2,324 websites

TLDs

.com40,283 websites
.org3,951 websites
.fr3,775 websites
.nl3,544 websites
.de3,118 websites
.it3,067 websites
.co.uk2,936 websites
.com.br2,506 websites
.net2,254 websites
.pl1,689 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2023-23880 through included software libraries and plugins.



References


Websites affected by CVE-2023-23880

Top websites that are affected by CVE-2023-23880. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
*********.com United States*,***
*********.com United States*,***
*********.com United States*,***
*********.com United States*,***
**********.com United States*,***
*****************.****************.com United States*,***
*********.com United States*,***
*********.com United States*,***
*****************.*********.com United States*,***
***.***************.com South Africa*,***
See full domain list