CVE-2023-3129

URL Shortify < 1.7.0 - Admin+ Cross Site Scripting

The URL Shortify WordPress plugin before 1.7.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)


We have discovered 196 live websites that are affected by CVE-2023-3129.

Run a Free Instant Scan




Affected Software

Product  Url Shortify
Category Wordpress Plugins
Vulnerable Domains196 live websites (4.27% of Url Shortify install base)
Vulnerable Versions
  • from 0 through 1.7
Vulnerable Versions Count27 versions ( 35% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Jul 10, 2023
  • Updated - Nov 12, 2024

Credits

  • Bob Matyas (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2023-3129
United States48 websites



Germany32 websites
France16 websites
Russia8 websites
Italy7 websites
Poland6 websites
Iran6 websites
Brazil6 websites
Canada5 websites
Spain5 websites

Website Distribution by TLD

Number of websites using CVE-2023-3129
.com81 websites
.de14 websites
.org14 websites
.net10 websites
.ru5 websites
.it4 websites
.at3 websites
.fr3 websites
.com.br3 websites
.cz3 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2023-3129

Top websites that are affected by CVE-2023-3129. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***************.de Germany**,***
******.com Germany***,***
**************.pro Poland***,***
***********.com Canada***,***
************.*******.com France*,***,***
*******.de Germany*,***,***
************.pl Poland*,***,***
*********.de Germany*,***,***
*****.md United States*,***,***
**********.***.vn Vietnam*,***,***
See full domain list

FAQ

CVE-2023-3129 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Url Shortify
A total of 196 websites have been identified as vulnerable to CVE-2023-3129, based on global website indexing conducted by WebTechSurvey.
The Url Shortify is affected by the CVE-2023-3129 vulnerability.
Url Shortify versions up to 1.7 are vulnerable to CVE-2023-3129.
CVE-2023-3129 is resolved in version 1.7 of Url Shortify.