CVE-2023-23999


WordPress Google Analytics by Monster Insights Plugin <= 8.14.0 is vulnerable to Cross Site Scripting (XSS)

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in MonsterInsights plugin <= 8.14.0 versions.



We have discovered 266,198 live websites that are affected by CVE-2023-23999.

Contact us to get more info




Affected Software

Product  MonsterInsights
Category Analytics
Vulnerable Versions
  • from 0 through 8.14
Total Vulnerable Versions145
Vulnerable Domains266,198 live websites (29.58% of MonsterInsights install base)


Common Weakness Enumeration


CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - May 18, 2023
  • Updated - May 18, 2023

Credits

  • Rafie Muhammad (Patchstack) (finder)





Countries

United States79,654 websites



Japan17,110 websites
France14,973 websites
GB13,757 websites
Germany13,414 websites
Italy11,792 websites
Poland9,838 websites
Netherlands9,800 websites
Spain8,288 websites
Canada6,789 websites

TLDs

.com123,604 websites
.org11,318 websites
.co.uk7,960 websites
.nl7,879 websites
.it7,664 websites
.pl7,663 websites
.net7,010 websites
.de6,630 websites
.fr5,971 websites
.com.br5,217 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


References


Websites affected by CVE-2023-23999

Top websites that are affected by CVE-2023-23999. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
************.***.ar Argentina*,***
***.*************.com United States*,***
***.**********.com United States*,***
*****.org United States*,***
****.******.net United States*,***
********.com United States*,***
***.*********.com GB**,***
***.**********.de Germany**,***
***.**********.com Ireland**,***
***********.me Canada**,***
See full domain list