CVE-2023-45607


WordPress WordPress Popular Posts Plugin <= 6.3.2 is vulnerable to Cross Site Scripting (XSS)

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Hector Cabrera WordPress Popular Posts plugin <= 6.3.2 versions.



We have discovered 9,489 live websites that are affected by CVE-2023-45607.

Contact us to get more info




Affected Software

Product  WordPress Popular Posts
Category Wordpress Plugins
Vulnerable Versions
  • from 0 through 6.3.2
Total Vulnerable Versions81
Vulnerable Domains9,489 live websites (43.08% of WordPress Popular Posts install base)


Common Weakness Enumeration


CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Oct 18, 2023
  • Updated - Oct 18, 2023

Credits

  • Rafie Muhammad (Patchstack) (finder)





Countries

United States2,179 websites



Japan3,948 websites
Germany383 websites
France266 websites
GB235 websites
Poland204 websites
Russia188 websites
Spain171 websites
Italy159 websites

TLDs

.com4,826 websites
.jp784 websites
.net583 websites
.org326 websites
.co.jp295 websites
.de199 websites
.ru153 websites
.info139 websites
.pl139 websites
.fr119 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


References


Websites affected by CVE-2023-45607

Top websites that are affected by CVE-2023-45607. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.*******.***.in India*,***
*********.com United States*,***
***.**********.com United States*,***
***************.com United States**,***
*******************.com Japan**,***
********.tokyo Japan**,***
*****.***.**.uk GB**,***
***.*******.edu United States**,***
******.com United States**,***
***.***************.com United States**,***
See full domain list