CVE-2023-47786

WordPress LayerSlider Plugin <= 7.7.9 is vulnerable to Cross Site Scripting (XSS)

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LayerSlider plugin <= 7.7.9 versions.


We have discovered 209,425 live websites that are affected by CVE-2023-47786.

Run a Free Instant Scan




Affected Software

Product  LayerSlider
Category Widgets
Vulnerable Domains209,425 live websites (75% of LayerSlider install base)
Vulnerable Versions
  • from 0 through 7.7.9
Vulnerable Versions Count116 versions ( 77% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Nov 22, 2023
  • Updated - Aug 2, 2024

Credits

  • Rafie Muhammad (Patchstack) (finder)

Website Distribution by Country

Number of websites using CVE-2023-47786
United States55,138 websites



Germany24,159 websites
Italy14,491 websites
France12,907 websites
GB9,386 websites
Spain8,959 websites
Netherlands7,260 websites
Canada4,790 websites
Poland4,597 websites
Brazil4,324 websites

Website Distribution by TLD

Number of websites using CVE-2023-47786
.com86,521 websites
.de13,655 websites
.it10,012 websites
.org8,157 websites
.nl6,369 websites
.co.uk6,035 websites
.fr4,963 websites
.com.br4,177 websites
.net4,131 websites
.es3,749 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2023-47786

Top websites that are affected by CVE-2023-47786. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*************.com United States*,***
******************.cat Spain*,***
*******.com Portugal**,***
*******.com United States**,***
*************.***.pk Pakistan**,***
******.ch Switzerland**,***
***********.com United States**,***
***********.com Netherlands**,***
*************.com United States**,***
********************.com Japan**,***
See full domain list

FAQ

CVE-2023-47786 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in LayerSlider
A total of 209,425 websites have been identified as vulnerable to CVE-2023-47786, based on global website indexing conducted by WebTechSurvey.
The LayerSlider is affected by the CVE-2023-47786 vulnerability.
LayerSlider versions up to and including 7.7.9 are vulnerable to CVE-2023-47786.