CVE-2023-45747


WordPress WP Lightbox 2 Plugin <= 3.0.6.5 is vulnerable to Cross Site Scripting (XSS)

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Syed Balkhi WP Lightbox 2 plugin <= 3.0.6.5 versions.



We have discovered 1,130 live websites that are affected by CVE-2023-45747.

Contact us to get more info




Affected Software

Product  WP Lightbox 2
Category Wordpress Plugins
Vulnerable Versions
  • from 0 through 3.0.6.5
Total Vulnerable Versions3
Vulnerable Domains1,130 live websites (100.00% of WP Lightbox 2 install base)


Common Weakness Enumeration


CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2023-45747 and the relative popularity of websites


Details

  • Published - Oct 24, 2023
  • Updated - Oct 24, 2023

Credits

  • Rio Darmawan (Patchstack Alliance) (finder)





Countries

United States301 websites



Japan133 websites
Canada132 websites
Germany110 websites
Russia61 websites
Poland59 websites
France57 websites
Italy30 websites
GB23 websites
Czech Republic17 websites

TLDs

.com519 websites
.de75 websites
.net56 websites
.ru49 websites
.jp44 websites
.pl43 websites
.org42 websites
.fr31 websites
.it15 websites
.ca15 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2023-45747 through included software libraries and plugins.



References


Websites affected by CVE-2023-45747

Top websites that are affected by CVE-2023-45747. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
***.**************.com Germany**,***
***.**************.com Czech Republic**,***
***.***************.com United States**,***
***.***************.jp Japan***,***
**************.com United States***,***
*****.********.gov United States***,***
***.*****.jp Japan***,***
********.net Russia***,***
******.com United States***,***
*****.*******.tk Tokelau***,***
See full domain list