CVE-2023-28782


WordPress Gravity Forms Plugin <= 2.7.3 is vulnerable to PHP Object Injection

Deserialization of Untrusted Data vulnerability in Rocketgenius Inc. Gravity Forms.This issue affects Gravity Forms: from n/a through 2.7.3.



We have discovered 164,060 live websites that are affected by CVE-2023-28782.

Contact us to get more info




Affected Software

Product  Gravity Forms
Category Wordpress Plugins
Vulnerable Versions
  • from 0 through 2.7.3
Total Vulnerable Versions496
Vulnerable Domains164,060 live websites (29.12% of Gravity Forms install base)


Common Weakness Enumeration


CWE-502 Deserialization of Untrusted Data


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2023-28782 and the relative popularity of websites


Details

  • Published - Dec 20, 2023
  • Updated - Dec 20, 2023

Credits

  • Rafie Muhammad (Patchstack) (finder)





Countries

United States82,984 websites



GB11,711 websites
Australia10,502 websites
Canada9,365 websites
Netherlands7,606 websites
France7,562 websites
Germany3,795 websites
Italy2,911 websites
Iran2,580 websites
Spain2,238 websites

TLDs

.com91,500 websites
.org9,326 websites
.com.au8,539 websites
.co.uk7,154 websites
.nl6,396 websites
.ca4,662 websites
.fr3,938 websites
.net3,588 websites
.de2,192 websites
.it1,892 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2023-28782 through included software libraries and plugins.



References


Websites affected by CVE-2023-28782

Top websites that are affected by CVE-2023-28782. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
***.*****.com Switzerland***
***.**********.com United States*,***
***.************.com United States*,***
***.**********.com United States*,***
***.***********.com United States*,***
************.com United States*,***
*******.com United States*,***
***.************.ie Ireland*,***
***.******.com France*,***
************.net United States*,***
See full domain list