CVE-2023-29100


WordPress The7 Theme <= 11.6.0 is vulnerable to Cross Site Scripting (XSS)

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Dream-Theme The7 plugin <= 11.6.0 versions.



We have discovered 25,216 live websites that are affected by CVE-2023-29100.

Contact us to get more info




Affected Software

Product  The7
Category Wordpress Themes
Vulnerable Versions
  • from 0 through 11.6
Total Vulnerable Versions203
Vulnerable Domains25,216 live websites (38.26% of The7 install base)


Common Weakness Enumeration


CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2023-29100 and the relative popularity of websites


Details

  • Published - Jun 23, 2023
  • Updated - Jun 23, 2023

Credits

  • Rafie Muhammad (Patchstack) (finder)





Countries

United States5,337 websites



Germany2,918 websites
Italy1,667 websites
France1,478 websites
Spain1,404 websites
GB1,205 websites
Netherlands1,067 websites
Russia765 websites
Turkey608 websites
Brazil584 websites

TLDs

.com9,747 websites
.de2,117 websites
.it1,134 websites
.org923 websites
.nl901 websites
.co.uk722 websites
.fr612 websites
.ru568 websites
.es566 websites
.com.br504 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2023-29100 through included software libraries and plugins.



References


Websites affected by CVE-2023-29100

Top websites that are affected by CVE-2023-29100. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
***********.com United States**,***
***.*******.com United States**,***
****.********.com GB**,***
****************.org United States**,***
***.*******.com United States**,***
*******.hu Hungary**,***
***.*********.com United States**,***
***.**********************.***.br Brazil**,***
***.***************.de Germany**,***
***********.com ***,***
See full domain list