CVE-2023-24408


WordPress Ecwid Shopping Cart Plugin <= 6.11.4 is vulnerable to Cross Site Scripting (XSS)

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Ecwid Ecommerce Ecwid Ecommerce Shopping Cart plugin <= 6.11.4 versions.



We have discovered 645 live websites that are affected by CVE-2023-24408.

Contact us to get more info




Affected Software

Product  Ecwid Ecommerce Shopping Cart
Category Wordpress Plugins
Vulnerable Versions
  • from 0 through 6.11.4
Total Vulnerable Versions124
Vulnerable Domains645 live websites (22.92% of Ecwid Ecommerce Shopping Cart install base)


Common Weakness Enumeration


CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2023-24408 and the relative popularity of websites


Details

  • Published - May 8, 2023
  • Updated - May 8, 2023

Credits

  • Lana Codes (Patchstack Alliance) (finder)





Countries

United States337 websites



Germany44 websites
GB42 websites
Italy28 websites
Canada25 websites
Russia21 websites
Australia20 websites
South Africa13 websites
France13 websites
Belgium12 websites

TLDs

.com379 websites
.org61 websites
.co.uk22 websites
.de21 websites
.it17 websites
.com.au17 websites
.ru14 websites
.net14 websites
.be10 websites
.ca9 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2023-24408 through included software libraries and plugins.



References


Websites affected by CVE-2023-24408

Top websites that are affected by CVE-2023-24408. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
***.****.org United States***,***
**************.com United States***,***
***.*************************.org United States***,***
*************.org United States***,***
*****************.org United States***,***
***.*********.com United States***,***
**********************.com Cyprus***,***
********.com Russia***,***
******************.org United States***,***
****.org United States***,***
See full domain list