CVE-2023-28994


WordPress Flatsome Theme <= 3.16.8 is vulnerable to Cross Site Scripting (XSS)

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in UX-themes Flatsome plugin <= 3.16.8 versions.



We have discovered 7,284 live websites that are affected by CVE-2023-28994.

Contact us to get more info




Affected Software

Product  Flatsome
Category Wordpress Themes
Vulnerable Versions
  • from 0 through 3.16.8
Total Vulnerable Versions153
Vulnerable Domains7,284 live websites (48.92% of Flatsome install base)


Common Weakness Enumeration


CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Aug 23, 2023
  • Updated - Aug 23, 2023

Credits

  • Rafie Muhammad (Patchstack) (finder)





Countries

United States1,752 websites



Vietnam1,529 websites
Germany551 websites
GB314 websites
Netherlands307 websites
France235 websites
Spain212 websites
Italy196 websites
Australia166 websites
Sweden122 websites

TLDs

.com3,117 websites
.de362 websites
.net282 websites
.nl266 websites
.org257 websites
.co.uk156 websites
.com.au126 websites
.it106 websites
.fr101 websites
.se95 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


References


Websites affected by CVE-2023-28994

Top websites that are affected by CVE-2023-28994. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.**********.com Singapore**,***
*********.net Vietnam**,***
***************.com United States**,***
****************.com United States**,***
***.********.se Sweden**,***
************.com Vietnam**,***
*********.**.il Israel**,***
***********.com United States**,***
***.******.com GB**,***
**********.com United States**,***
See full domain list