CVE-2023-46211

WordPress Ultimate Addons for WPBakery Page Builder Plugin <= 3.19.14 is vulnerable to Cross Site Scripting (XSS)

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Brainstorm Force Ultimate Addons for WPBakery Page Builder plugin <= 3.19.14 versions.


We have discovered 95,580 live websites that are affected by CVE-2023-46211.

Test my site




Affected Software

Product  Visual Composer Ultimate Addons
Category Widgets
Vulnerable Domains95,580 live websites (64.64% of Visual Composer Ultimate Addons install base)
Vulnerable Versions
  • from 0 through 3.19.14
Vulnerable Versions Count87 versions ( 83.65% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Oct 27, 2023
  • Updated - Sep 6, 2024

Credits

  • Rafie Muhammad (Patchstack) (finder)

CVE-2023-46211 usage by Country

United States29,966 websites



Germany11,568 websites
France6,332 websites
GB3,904 websites
Spain3,267 websites
Italy3,244 websites
Russia3,184 websites
Netherlands2,535 websites
Poland2,225 websites
Australia1,846 websites

CVE-2023-46211 usage by TLD

.com39,262 websites
.de5,509 websites
.org3,161 websites
.co.uk2,906 websites
.it2,902 websites
.ru2,548 websites
.nl2,379 websites
.com.au2,264 websites
.fr2,057 websites
.com.br1,991 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2023-46211

Top websites that are affected by CVE-2023-46211. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****************.com United States**,***
*******.de Germany**,***
**********.com United States**,***
********.com United States**,***
************.com United States**,***
*********.com United States**,***
*********.com United States**,***
***.com United States**,***
*******.com United States**,***
**************************.pt Portugal**,***
See full domain list

FAQ

CVE-2023-46211 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Visual Composer Ultimate Addons
A total of 95,580 websites have been identified as vulnerable to CVE-2023-46211, discovered through global website indexing conducted by WebTechSurvey.
Visual Composer Ultimate Addons is susceptible to CVE-2023-46211 vulnerability.
Visual Composer Ultimate Addons versions before, and including, 3.19.14 are vulnerable to CVE-2023-46211.