CVE-2023-4648




The WP Customer Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 3.6.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.



We have discovered 587 live websites that are affected by CVE-2023-4648.

Contact us to get more info




Affected Software

Product  WP Customer Reviews
Category Wordpress Plugins
Vulnerable Versions
  • from 0 through 3.6.6
Total Vulnerable Versions46
Vulnerable Domains587 live websites (59.65% of WP Customer Reviews install base)


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2023-4648 and the relative popularity of websites


Details

  • Published - Oct 20, 2023
  • Updated - Oct 20, 2023

Credits

  • Marco Wotschka (finder)




Countries

United States282 websites



GB49 websites
Russia42 websites
Japan41 websites
Germany26 websites
France26 websites
Netherlands17 websites
Italy11 websites
Australia10 websites
Canada9 websites

TLDs

.com339 websites
.ru37 websites
.co.uk34 websites
.org25 websites
.net20 websites
.nl14 websites
.jp11 websites
.fr11 websites
.de9 websites
.it8 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2023-4648 through included software libraries and plugins.



References


Websites affected by CVE-2023-4648

Top websites that are affected by CVE-2023-4648. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
**********************.com United States**,***
***.**********************.com United States***,***
***.******************.com United States***,***
******.com United States***,***
******.nl Netherlands***,***
***.************.com Germany***,***
**************.org United States***,***
******************.com Japan***,***
**********.de Germany***,***
****************.com United States***,***
See full domain list