CVE-2023-38383

WordPress Language plugin <= 1.2.1 - Broken Access Control vulnerability

Missing Authorization vulnerability in OnTheGoSystems Language allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Language: from n/a through 1.2.1.


We have discovered 860 live websites that are affected by CVE-2023-38383.

Run a Free Instant Scan




Affected Software

Product  Wordpress Language
Category Wordpress Plugins
Vulnerable Domains860 live websites (100% of Wordpress Language install base)
Vulnerable Versions
  • from 0 through 1.2.1
Vulnerable Versions Count2 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-862 Missing Authorization



Details

  • Published - Dec 13, 2024
  • Updated - Dec 13, 2024

Credits

  • Abdi Pranata (Patchstack Alliance) (finder)

Website Distribution by Country

Number of websites using CVE-2023-38383
United States107 websites



Germany129 websites
Switzerland67 websites
Netherlands64 websites
Italy49 websites
France37 websites
Sweden30 websites
Denmark30 websites
Austria28 websites
Czech Republic27 websites

Website Distribution by TLD

Number of websites using CVE-2023-38383
.com206 websites
.de67 websites
.ch64 websites
.nl60 websites
.it36 websites
.org34 websites
.at29 websites
.net29 websites
.se23 websites
.cz22 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2023-38383

Top websites that are affected by CVE-2023-38383. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
************.com Israel**,***
*********.***.uk GB**,***
*****.com Japan***,***
*********.***.in India***,***
********************.cz Czech Republic***,***
**********.it Italy***,***
*****.com Poland***,***
***********************.nl United States***,***
*******************.nl United States*,***,***
****.***.pr Puerto Rico*,***,***
See full domain list

FAQ

CVE-2023-38383 is Missing Authorization in Wordpress Language
A total of 860 websites have been identified as vulnerable to CVE-2023-38383, based on global website indexing conducted by WebTechSurvey.
The Wordpress Language is affected by the CVE-2023-38383 vulnerability.
Wordpress Language versions up to and including 1.2.1 are vulnerable to CVE-2023-38383.