CVE-2023-2496

The Go Pricing - WordPress Responsive Pricing Tables plugin for WordPress is vulnerable to unauthorized arbitrary file uploads due to an improper capability check on the 'validate_upload' function in versions up to, and including, 3.3.19. This makes it possible for authenticated attackers with a role that the administrator previously granted access to the plugin to upload arbitrary files on the affected site's server which may make remote code execution possible.


We have discovered 11,228 live websites that are affected by CVE-2023-2496.

Run a Free Instant Scan




Affected Software

Product  Go Pricing
Category Wordpress Plugins
Vulnerable Domains11,228 live websites (100% of Go Pricing install base)
Vulnerable Versions
  • from 0 through 3.3.19
Vulnerable Versions Count0 versions ( less than 0.1% of all versions)



Details

  • Published - May 23, 2023
  • Updated - Jan 13, 2025

Credits

  • Lana Codes (finder)

Website Distribution by Country

Number of websites using CVE-2023-2496
United States2,899 websites



Germany1,024 websites
Italy731 websites
France712 websites
GB554 websites
Russia492 websites
Spain471 websites
Netherlands398 websites
Poland268 websites
Australia238 websites

Website Distribution by TLD

Number of websites using CVE-2023-2496
.com4,667 websites
.de569 websites
.it534 websites
.ru390 websites
.co.uk342 websites
.nl341 websites
.org316 websites
.fr249 websites
.net246 websites
.es235 websites

Websites affected by CVE-2023-2496

Top websites that are affected by CVE-2023-2496. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***********.com United States**,***
*******.com United States**,***
*******.com United States**,***
********.com Bulgaria**,***
***********.com United States**,***
*******.hu Hungary**,***
****.***.uk United States**,***
*******.eu Hungary**,***
************************.com United States**,***
********.com Singapore***,***
See full domain list

FAQ

A total of 11,228 websites have been identified as vulnerable to CVE-2023-2496, based on global website indexing conducted by WebTechSurvey.
The Go Pricing is affected by the CVE-2023-2496 vulnerability.
Go Pricing versions up to and including 3.3.19 are vulnerable to CVE-2023-2496.