CVE-2023-23999

WordPress Google Analytics by Monster Insights Plugin <= 8.14.0 is vulnerable to Cross Site Scripting (XSS)

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in MonsterInsights plugin <= 8.14.0 versions.


We have discovered 172,740 live websites that are affected by CVE-2023-23999.

Test my site




Affected Software

Product  MonsterInsights
Category Analytics
Vulnerable Domains172,740 live websites (20.85% of MonsterInsights install base)
Vulnerable Versions
  • from 0 through 8.14
Vulnerable Versions Count126 versions ( 79.25% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - May 18, 2023
  • Updated - Jan 9, 2025

Credits

  • Rafie Muhammad (Patchstack) (finder)

CVE-2023-23999 usage by Country

United States58,704 websites



Germany14,880 websites
Japan12,680 websites
France11,524 websites
Poland6,700 websites
GB6,541 websites
Netherlands5,709 websites
Spain4,266 websites
Italy4,220 websites
Cyprus2,985 websites

CVE-2023-23999 usage by TLD

.com78,629 websites
.org6,872 websites
.pl5,454 websites
.nl5,227 websites
.co.uk4,941 websites
.de4,812 websites
.net4,651 websites
.fr4,098 websites
.it3,418 websites
.com.au3,310 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2023-23999

Top websites that are affected by CVE-2023-23999. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
************.***.ar Argentina*,***
*************.com United States*,***
**********.com United States*,***
*****.org United States*,***
****.******.net United States*,***
*********.com Sweden**,***
**********.de Germany**,***
***********.me Canada**,***
********.********.edu United States**,***
**********.com United States**,***
See full domain list

FAQ

CVE-2023-23999 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in MonsterInsights
A total of 172,740 websites have been identified as vulnerable to CVE-2023-23999, discovered through global website indexing conducted by WebTechSurvey.
MonsterInsights is susceptible to CVE-2023-23999 vulnerability.
MonsterInsights versions before, and including, 8.14 are vulnerable to CVE-2023-23999.