CVE-2023-23900


WordPress Easy Forms for Mailchimp Plugin <= 6.8.8 is vulnerable to Cross Site Scripting (XSS)

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in YIKES, Inc. Easy Forms for Mailchimp plugin <= 6.8.8 versions.



We have discovered 1,778 live websites that are affected by CVE-2023-23900.

Contact us to get more info




Affected Software

Product  Easy Forms for Mailchimp
Category Wordpress Plugins
Vulnerable Versions
  • from 0 through 6.8.8
Total Vulnerable Versions64
Vulnerable Domains1,778 live websites (35.83% of Easy Forms for Mailchimp install base)


Common Weakness Enumeration


CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2023-23900 and the relative popularity of websites


Details

  • Published - Aug 10, 2023
  • Updated - Aug 10, 2023

Credits

  • Rafie Muhammad (Patchstack) (finder)





Countries

United States605 websites



Italy171 websites
GB125 websites
Germany87 websites
France80 websites
Australia63 websites
Netherlands63 websites
Spain60 websites
Canada56 websites
Brazil32 websites

TLDs

.com855 websites
.org131 websites
.it97 websites
.co.uk51 websites
.com.au41 websites
.nl39 websites
.de37 websites
.fr33 websites
.net29 websites
.com.br25 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2023-23900 through included software libraries and plugins.



References


Websites affected by CVE-2023-23900

Top websites that are affected by CVE-2023-23900. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
************.com United States**,***
*************.com United States**,***
*********.net United States***,***
***.******************.com United States***,***
************.**.uk GB***,***
*****.tv Netherlands***,***
***.**********.com United States***,***
****.com United States***,***
****.*******.com Denmark***,***
********.*******.com United States***,***
See full domain list