CVE-2023-29101

WordPress Betheme Theme <= 26.7.5 is vulnerable to Cross Site Scripting (XSS)

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Muffingroup Betheme theme <= 26.7.5 versions.


We have discovered 65,325 live websites that are affected by CVE-2023-29101.

Test my site




Affected Software

Product  BeTheme
Category Wordpress Themes
Vulnerable Domains65,325 live websites (58.95% of BeTheme install base)
Vulnerable Versions
  • from 0 through 26.7.5
Vulnerable Versions Count524 versions ( 86.18% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - May 10, 2023
  • Updated - Jan 13, 2025

Credits

  • Rafie Muhammad (Patchstack) (finder)

CVE-2023-29101 usage by Country

United States18,915 websites



Germany8,883 websites
France3,929 websites
Brazil2,776 websites
Italy2,347 websites
Poland2,207 websites
GB1,923 websites
Spain1,843 websites
Netherlands1,631 websites
Russia1,598 websites

CVE-2023-29101 usage by TLD

.com24,386 websites
.de4,269 websites
.com.br3,547 websites
.fr2,556 websites
.it2,034 websites
.org1,900 websites
.pl1,749 websites
.nl1,612 websites
.ru1,286 websites
.co.uk1,235 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2023-29101

Top websites that are affected by CVE-2023-29101. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.nl United States*,***
*****************.com United States**,***
******.fr France**,***
**********.com United States**,***
**********.com United States**,***
***********.com Singapore***,***
*******.**.ke Kenya***,***
*******.de Germany***,***
*******.com United States***,***
********.at Germany***,***
See full domain list

FAQ

CVE-2023-29101 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in BeTheme
A total of 65,325 websites have been identified as vulnerable to CVE-2023-29101, discovered through global website indexing conducted by WebTechSurvey.
BeTheme is susceptible to CVE-2023-29101 vulnerability.
BeTheme versions before, and including, 26.7.5 are vulnerable to CVE-2023-29101.