CVE-2023-29101


WordPress Betheme Theme <= 26.7.5 is vulnerable to Cross Site Scripting (XSS)

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Muffingroup Betheme theme <= 26.7.5 versions.



We have discovered 8,077 live websites that are affected by CVE-2023-29101.

Contact us to get more info




Affected Software

Product  BeTheme
Category Wordpress Themes
Vulnerable Versions
  • from 0 through 26.7.5
Total Vulnerable Versions512
Vulnerable Domains8,077 live websites (60.35% of BeTheme install base)


Common Weakness Enumeration


CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2023-29101 and the relative popularity of websites


Details

  • Published - May 10, 2023
  • Updated - May 10, 2023

Credits

  • Rafie Muhammad (Patchstack) (finder)





Countries

United States1,901 websites



Germany1,156 websites
France591 websites
Italy470 websites
Spain325 websites
GB294 websites
Netherlands270 websites
Poland263 websites
Brazil250 websites
Canada186 websites

TLDs

.com2,923 websites
.de796 websites
.org565 websites
.it288 websites
.fr273 websites
.nl211 websites
.pl200 websites
.com.br189 websites
.net172 websites
.co.uk132 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2023-29101 through included software libraries and plugins.



References


Websites affected by CVE-2023-29101

Top websites that are affected by CVE-2023-29101. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
***.*********.nl Netherlands*,***
***.*************.com United States**,***
*******.org Spain**,***
***.buzz United States**,***
*****************.com United States**,***
***.******.fr France**,***
***.****************************.com United States**,***
**********.com United States**,***
**********.com United States**,***
*************.com United States**,***
See full domain list