CVE-2023-23996


WordPress ProfilePress Plugin <= 4.5.3 is vulnerable to Cross Site Scripting (XSS)

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in ProfilePress Membership Team ProfilePress plugin <= 4.5.3 versions.



We have discovered 3,380 live websites that are affected by CVE-2023-23996.

Contact us to get more info




Affected Software

Product  ProfilePress
Category Wordpress Plugins
Vulnerable Versions
  • from 0 through 4.5.3
Total Vulnerable Versions95
Vulnerable Domains3,380 live websites (17.23% of ProfilePress install base)


Common Weakness Enumeration


CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2023-23996 and the relative popularity of websites


Details

  • Published - Apr 6, 2023
  • Updated - Apr 6, 2023

Credits

  • Rio Darmawan (Patchstack Alliance) (finder)





Countries

United States1,078 websites



Japan365 websites
Germany288 websites
France175 websites
GB149 websites
Italy141 websites
Poland100 websites
Spain99 websites
Brazil90 websites
Canada59 websites

TLDs

.com1,564 websites
.de178 websites
.org177 websites
.net114 websites
.it91 websites
.jp85 websites
.co.uk74 websites
.com.br72 websites
.pl71 websites
.fr64 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2023-23996 through included software libraries and plugins.



References


Websites affected by CVE-2023-23996

Top websites that are affected by CVE-2023-23996. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
***.**********.com United States*,***
*********.com Japan**,***
***.*****.com United States**,***
***.****************.com United States**,***
***.******.com United States**,***
************.com United States**,***
***************.net United States**,***
******.com Estonia**,***
************.com United States**,***
************.com Japan**,***
See full domain list