CVE-2023-34378


WordPress WP Hide Post Plugin <= 2.0.10 is vulnerable to Cross Site Request Forgery (CSRF)

Cross-Site Request Forgery (CSRF) vulnerability in scriptburn.Com WP Hide Post plugin <= 2.0.10 versions.



We have discovered 7,941 live websites that are affected by CVE-2023-34378.

Contact us to get more info




Affected Software

Product  WP Hide Post
Category Wordpress Plugins
Vulnerable Versions
  • from 0 through 2.0.10
Total Vulnerable Versions4
Vulnerable Domains7,941 live websites (99.40% of WP Hide Post install base)


Common Weakness Enumeration


CWE-352 Cross-Site Request Forgery (CSRF)


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2023-34378 and the relative popularity of websites


Details

  • Published - Nov 13, 2023
  • Updated - Nov 13, 2023

Credits

  • Lana Codes (Patchstack Alliance) (finder)





Countries

United States3,111 websites



Germany926 websites
France405 websites
GB380 websites
Netherlands284 websites
Russia257 websites
Poland224 websites
Canada165 websites
Spain147 websites
Italy141 websites

TLDs

.com3,637 websites
.de607 websites
.org552 websites
.net287 websites
.nl208 websites
.ru189 websites
.co.uk188 websites
.pl182 websites
.fr139 websites
.it83 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2023-34378 through included software libraries and plugins.



References


Websites affected by CVE-2023-34378

Top websites that are affected by CVE-2023-34378. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
***.***************.com United States*,***
***.*******************.ro Romania**,***
***************.dk Denmark**,***
***.***.org United States**,***
***.**********.com United States**,***
***.*******.net Turkey**,***
****.*****.com United States**,***
*********.com United States**,***
*********.in India**,***
***********.com United States**,***
See full domain list