CVE-2023-24377


WordPress Ecwid Shopping Cart Plugin <= 6.11.3 is vulnerable to Cross Site Request Forgery (CSRF)

Cross-Site Request Forgery (CSRF) vulnerability in Ecwid Ecommerce Ecwid Ecommerce Shopping Cart plugin <= 6.11.3 versions.



We have discovered 614 live websites that are affected by CVE-2023-24377.

Contact us to get more info




Affected Software

Product  Ecwid Ecommerce Shopping Cart
Category Wordpress Plugins
Vulnerable Versions
  • from 0 through 6.11.3
Total Vulnerable Versions124
Vulnerable Domains614 live websites (21.82% of Ecwid Ecommerce Shopping Cart install base)


Common Weakness Enumeration


CWE-352 Cross-Site Request Forgery (CSRF)


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2023-24377 and the relative popularity of websites


Details

  • Published - Feb 14, 2023
  • Updated - Feb 14, 2023

Credits

  • Lana Codes (Patchstack Alliance) (finder)





Countries

United States322 websites



GB40 websites
Germany39 websites
Italy26 websites
Canada25 websites
Russia21 websites
Australia19 websites
South Africa13 websites
France12 websites
Belgium11 websites

TLDs

.com362 websites
.org55 websites
.co.uk22 websites
.de20 websites
.it16 websites
.com.au16 websites
.ru14 websites
.net13 websites
.be9 websites
.ca9 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2023-24377 through included software libraries and plugins.



References


Websites affected by CVE-2023-24377

Top websites that are affected by CVE-2023-24377. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
***.****.org United States***,***
**************.com United States***,***
*************.org United States***,***
*****************.org United States***,***
***.*********.com United States***,***
**********************.com Cyprus***,***
********.com Russia***,***
******************.org United States***,***
****.org United States***,***
**********.org United States***,***
See full domain list