CVE-2023-34172


WordPress WordPress Social Login Plugin <= 3.0.4 is vulnerable to Cross Site Scripting (XSS)

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Miled WordPress Social Login plugin <= 3.0.4 versions.



We have discovered 4,289 live websites that are affected by CVE-2023-34172.

Contact us to get more info




Affected Software

Product  WordPress Social Login
Category Wordpress Plugins
Vulnerable Versions
  • from 0 through 3.0.4
Total Vulnerable Versions28
Vulnerable Domains4,289 live websites (98.21% of WordPress Social Login install base)


Common Weakness Enumeration


CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2023-34172 and the relative popularity of websites


Details

  • Published - Aug 30, 2023
  • Updated - Aug 30, 2023

Credits

  • yuyudhn (Patchstack Alliance) (finder)





Countries

United States1,281 websites



Russia293 websites
Italy259 websites
France216 websites
Germany214 websites
Spain147 websites
GB133 websites
Canada96 websites
India96 websites
Poland90 websites

TLDs

.com2,030 websites
.ru218 websites
.org164 websites
.it163 websites
.net152 websites
.pl74 websites
.com.br74 websites
.de72 websites
.fr62 websites
.co.uk58 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2023-34172 through included software libraries and plugins.



References


Websites affected by CVE-2023-34172

Top websites that are affected by CVE-2023-34172. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
************.com United States*,***
***.**************.org United States**,***
****************.com United States**,***
***.**********************.com United States**,***
**.ru Russia**,***
***.*********.com United States**,***
***.************.com Hong Kong***,***
***********.*************.com United States***,***
*******.us United States***,***
**************.com United States***,***
See full domain list