CVE-2023-38518

WordPress Borderless Plugin <= 1.4.8 is vulnerable to Cross Site Scripting (XSS)

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Visualmodo Borderless plugin <= 1.4.8 versions.


We have discovered 69 live websites that are affected by CVE-2023-38518.

Run a Free Instant Scan




Affected Software

Product  Borderless
Category Wordpress Plugins
Vulnerable Domains69 live websites (7.26% of Borderless install base)
Vulnerable Versions
  • from 0 through 1.4.8
Vulnerable Versions Count14 versions ( 47% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Sep 3, 2023
  • Updated - Apr 28, 2026

Credits

  • Rio Darmawan (Patchstack Alliance) (finder)

Website Distribution by Country

Number of websites using CVE-2023-38518
United States15 websites



Switzerland12 websites
France5 websites
South Africa5 websites
Netherlands4 websites
Austria2 websites
GB2 websites
Kenya2 websites
Malaysia2 websites
Slovakia2 websites

Website Distribution by TLD

Number of websites using CVE-2023-38518
.com21 websites
.ch12 websites
.org5 websites
.nl3 websites
.at2 websites
.co.uk1 websites
.com.br1 websites
.es1 websites
.fi1 websites
.fr1 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2023-38518

Top websites that are affected by CVE-2023-38518. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***************.fr France*,***,***
********.******.org United States*,***,***
**************.org United States*,***,***
*******************************.com United States*,***,***
***************************.nl Netherlands*,***,***
**********.com United States*,***,***
**********.com United States*,***,***
*********.**.ke Kenya*,***,***
****.*****************.com United States*,***,***
*******.com Thailand*,***,***
See full domain list

FAQ

CVE-2023-38518 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Borderless
A total of 69 websites have been identified as vulnerable to CVE-2023-38518, based on global website indexing conducted by WebTechSurvey.
The Borderless is affected by the CVE-2023-38518 vulnerability.
Borderless versions up to and including 1.4.8 are vulnerable to CVE-2023-38518.