CVE-2023-45747

WordPress WP Lightbox 2 Plugin <= 3.0.6.5 is vulnerable to Cross Site Scripting (XSS)

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Syed Balkhi WP Lightbox 2 plugin <= 3.0.6.5 versions.


We have discovered 22,682 live websites that are affected by CVE-2023-45747.

Test my site




Affected Software

Product  WP Lightbox 2
Category Wordpress Plugins
Vulnerable Domains22,682 live websites (100.00% of WP Lightbox 2 install base)
Vulnerable Versions
  • from 0 through 3.0.6.5
Vulnerable Versions Count5 versions ( 100.00% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Oct 24, 2023
  • Updated - Feb 19, 2025

Credits

  • Rio Darmawan (Patchstack Alliance) (finder)

CVE-2023-45747 usage by Country

United States3,754 websites



Germany4,462 websites
Japan2,981 websites
Poland1,655 websites
Russia1,504 websites
France1,388 websites
GB522 websites
Netherlands518 websites
Canada452 websites
Switzerland392 websites

CVE-2023-45747 usage by TLD

.com7,022 websites
.de3,285 websites
.ru1,374 websites
.pl1,263 websites
.org770 websites
.net724 websites
.jp671 websites
.fr613 websites
.nl473 websites
.co.jp402 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2023-45747

Top websites that are affected by CVE-2023-45747. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**************.pl Poland**,***
**************.com Czech Republic**,***
*****.**.gov United States**,***
****.**.gov United States**,***
************.com United States**,***
*******.org GB**,***
*****.com United States**,***
******.com United States**,***
***************.com Singapore**,***
****.eu GB**,***
See full domain list

FAQ

CVE-2023-45747 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in WP Lightbox 2
A total of 22,682 websites have been identified as vulnerable to CVE-2023-45747, discovered through global website indexing conducted by WebTechSurvey.
WP Lightbox 2 is susceptible to CVE-2023-45747 vulnerability.
WP Lightbox 2 versions before, and including, 3.0.6.5 are vulnerable to CVE-2023-45747.