CVE-2023-47777


WordPress WooCommerce and WooCommerce Blocks plugins - Auth. Cross-Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WooCommerce, Automattic WooCommerce Blocks allows Stored XSS.This issue affects WooCommerce: from n/a through 8.1.1; WooCommerce Blocks: from n/a through 11.1.1.



We have discovered 784,050 live websites that are affected by CVE-2023-47777.

Contact us to get more info




Affected Software

Product  WooCommerce
Category Ecommerce
Vulnerable Versions
  • from 0 through 8.1.1
Total Vulnerable Versions582
Vulnerable Domains784,050 live websites (60.67% of WooCommerce install base)


Common Weakness Enumeration


CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Nov 30, 2023
  • Updated - Nov 30, 2023

Credits

  • Rafie Muhammad (Patchstack) (finder)





Countries

United States187,629 websites



Germany44,372 websites
France43,101 websites
GB39,379 websites
Italy39,180 websites
Russia29,118 websites
Spain28,289 websites
Netherlands24,641 websites
Vietnam22,547 websites
Australia19,372 websites

TLDs

.com351,975 websites
.it25,143 websites
.ru22,707 websites
.co.uk22,644 websites
.de21,906 websites
.org20,764 websites
.nl19,076 websites
.fr15,820 websites
.com.au14,780 websites
.net14,694 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


References


Websites affected by CVE-2023-47777

Top websites that are affected by CVE-2023-47777. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******.at Austria*,***
***.***.com United States*,***
************.com United States*,***
***.***********.com Italy*,***
***********.com Germany*,***
***********.com United States*,***
*****************.com United States*,***
***.*************.com United States*,***
***.*************.com United States*,***
**********.com United States*,***
See full domain list