CVE-2023-29099


WordPress Divi Theme <= 4.20.2 is vulnerable to Cross Site Scripting (XSS)

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Elegant themes Divi theme <= 4.20.2 versions.



We have discovered 391,952 live websites that are affected by CVE-2023-29099.

Contact us to get more info




Affected Software

Product  Divi
Category Landing Page Builders
Vulnerable Versions
  • from 0 through 4.20.2
Total Vulnerable Versions864
Vulnerable Domains391,952 live websites (39.74% of Divi install base)


Common Weakness Enumeration


CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2023-29099 and the relative popularity of websites


Details

  • Published - Aug 8, 2023
  • Updated - Aug 8, 2023

Credits

  • Rafie Muhammad (Patchstack) (finder)





Countries

United States125,085 websites



Germany33,970 websites
France27,948 websites
GB25,842 websites
Spain18,238 websites
Netherlands16,453 websites
Italy15,935 websites
Canada12,526 websites
Australia11,728 websites
Poland10,678 websites

TLDs

.com172,905 websites
.de23,051 websites
.org17,396 websites
.co.uk16,584 websites
.nl13,808 websites
.fr12,413 websites
.it10,615 websites
.com.au9,209 websites
.pl8,024 websites
.net7,881 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2023-29099 through included software libraries and plugins.



References


Websites affected by CVE-2023-29099

Top websites that are affected by CVE-2023-29099. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
************.org France*,***
****************.com United States*,***
***.******.com France*,***
**************.de Germany**,***
***************.pl Poland**,***
***.**************.com United States**,***
******.fr France**,***
****************.org **,***
***************.com United States**,***
***********************.pl Poland**,***
See full domain list