CVE-2023-35917


WordPress WooCommerce PayPal Payments Plugin <= 2.0.4 is vulnerable to Cross Site Request Forgery (CSRF)

Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce PayPal Payments plugin <= 2.0.4 versions.



We have discovered 1,288 live websites that are affected by CVE-2023-35917.

Contact us to get more info




Affected Software

Product  WooCommerce PayPal Payments
Category Wordpress Plugins
Vulnerable Versions
  • from 0 through 2.0.4
Total Vulnerable Versions34
Vulnerable Domains1,288 live websites (10.27% of WooCommerce PayPal Payments install base)


Common Weakness Enumeration


CWE-352 Cross-Site Request Forgery (CSRF)


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2023-35917 and the relative popularity of websites


Details

  • Published - Jun 22, 2023
  • Updated - Jun 22, 2023

Credits

  • Rafie Muhammad (Patchstack) (finder)





Countries

United States453 websites



GB166 websites
Germany139 websites
Italy108 websites
France66 websites
Australia65 websites
Spain47 websites
Canada31 websites
Cyprus18 websites
Mexico13 websites

TLDs

.com703 websites
.co.uk101 websites
.de76 websites
.it71 websites
.org56 websites
.com.au52 websites
.fr28 websites
.net25 websites
.es17 websites
.ca14 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2023-35917 through included software libraries and plugins.



References


Websites affected by CVE-2023-35917

Top websites that are affected by CVE-2023-35917. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
***.*****.com Germany**,***
***.**************.com United States**,***
***.***********.com United States***,***
********.**.uk GB***,***
***.******************.com United States***,***
*******.*********.com India***,***
****************.de Germany***,***
***.********.net Germany***,***
********.com United States***,***
*************.**************.com United States***,***
See full domain list