CVE-2023-35882


WordPress Super Socializer Plugin <= 7.13.52 is vulnerable to Cross Site Scripting (XSS)

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Team Heateor Super Socializer plugin <= 7.13.52 versions.



We have discovered 2,956 live websites that are affected by CVE-2023-35882.

Contact us to get more info




Affected Software

Product  Super Socializer
Category Wordpress Plugins
Vulnerable Versions
  • from 0 through 7.13.52
Total Vulnerable Versions181
Vulnerable Domains2,956 live websites (43.90% of Super Socializer install base)


Common Weakness Enumeration


CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2023-35882 and the relative popularity of websites


Details

  • Published - Jun 20, 2023
  • Updated - Jun 20, 2023

Credits

  • Rafshanzani Suhada (Patchstack Alliance) (finder)





Countries

United States766 websites



Italy267 websites
Russia236 websites
France137 websites
Germany128 websites
GB102 websites
India100 websites
Brazil93 websites
Poland84 websites
Spain66 websites

TLDs

.com1,223 websites
.ru204 websites
.it182 websites
.org145 websites
.net87 websites
.com.br81 websites
.pl66 websites
.fr48 websites
.de46 websites
.co.uk44 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2023-35882 through included software libraries and plugins.



References


Websites affected by CVE-2023-35882

Top websites that are affected by CVE-2023-35882. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
***********.pro United States**,***
***********.ru Russia**,***
***********.bg Bulgaria**,***
***.******.com United States***,***
***.******.org United States***,***
**************.com Finland***,***
***.*************.com United States***,***
***.***********.com France***,***
***.***.ua Ukraine***,***
************.com France***,***
See full domain list