CVE-2023-2496

The Go Pricing - WordPress Responsive Pricing Tables plugin for WordPress is vulnerable to unauthorized arbitrary file uploads due to an improper capability check on the 'validate_upload' function in versions up to, and including, 3.3.19. This makes it possible for authenticated attackers with a role that the administrator previously granted access to the plugin to upload arbitrary files on the affected site's server which may make remote code execution possible.


We have discovered 12,603 live websites that are affected by CVE-2023-2496.

Test my site




Affected Software

Product  Go Pricing
Category Wordpress Plugins
Vulnerable Domains12,603 live websites (68.43% of Go Pricing install base)
Vulnerable Versions
  • from 0 through 3.3.19
Vulnerable Versions Count43 versions ( 84.31% of all versions)



Details

  • Published - May 23, 2023
  • Updated - Jan 13, 2025

Credits

  • Lana Codes (finder)

CVE-2023-2496 usage by Country

United States3,891 websites



Germany1,371 websites
France944 websites
Russia526 websites
GB520 websites
Spain476 websites
Netherlands440 websites
Italy417 websites
Poland311 websites
Australia231 websites

CVE-2023-2496 usage by TLD

.com5,329 websites
.de649 websites
.ru422 websites
.nl408 websites
.co.uk381 websites
.it380 websites
.org370 websites
.fr288 websites
.net277 websites
.es259 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2023-2496

Top websites that are affected by CVE-2023-2496. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***********.com United States**,***
***********.com United States**,***
*******.com United States**,***
*******.com United States**,***
********.com Bulgaria**,***
***********.com United States**,***
*******.hu Hungary**,***
****.***.uk United States**,***
*******.eu Hungary**,***
********.com Singapore***,***
See full domain list

FAQ

A total of 12,603 websites have been identified as vulnerable to CVE-2023-2496, discovered through global website indexing conducted by WebTechSurvey.
Go Pricing is susceptible to CVE-2023-2496 vulnerability.
Go Pricing versions before, and including, 3.3.19 are vulnerable to CVE-2023-2496.