CVE-2023-2584

The PixelYourSite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 9.3.6 (9.6.1 in the Pro version) due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.


We have discovered 69,137 live websites that are affected by CVE-2023-2584.

Test my site




Affected Software

Product  PixelYourSite
Category Analytics
Vulnerable Domains69,137 live websites (67.54% of PixelYourSite install base)
Vulnerable Versions
  • from 0 through 9.6.1
Vulnerable Versions Count165 versions ( 85.49% of all versions)



Details

  • Published - Jun 9, 2023
  • Updated - Feb 5, 2025

Credits

  • Marco Wotschka (finder)

CVE-2023-2584 usage by Country

United States26,732 websites



Germany5,734 websites
France3,371 websites
Brazil3,137 websites
Poland2,721 websites
Spain2,290 websites
Italy2,285 websites
Cyprus2,043 websites
Netherlands1,878 websites
GB1,819 websites

CVE-2023-2584 usage by TLD

.com30,173 websites
.com.br5,015 websites
.pl2,294 websites
.it2,203 websites
.nl1,873 websites
.de1,678 websites
.com.au1,589 websites
.co.uk1,512 websites
.dk1,251 websites
.es1,181 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2023-2584

Top websites that are affected by CVE-2023-2584. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***********.com United States*,***
*********.com United States*,***
*************.***.au United States**,***
**********.com United States**,***
*****.app Bulgaria**,***
*******.com United States**,***
**********.jp Japan**,***
************.org United States**,***
***********.org Germany**,***
*****************.**.uk United States**,***
See full domain list

FAQ

A total of 69,137 websites have been identified as vulnerable to CVE-2023-2584, discovered through global website indexing conducted by WebTechSurvey.
PixelYourSite is susceptible to CVE-2023-2584 vulnerability.
PixelYourSite versions before, and including, 9.6.1 are vulnerable to CVE-2023-2584.