CVE-2023-4823

WP Meta and Date Remover < 2.2.0 - Subscriber+ Stored XSS

The WP Meta and Date Remover WordPress plugin before 2.2.0 provides an AJAX endpoint for configuring the plugin settings. This endpoint has no capability checks and does not sanitize the user input, which is then later output unescaped. Allowing any authenticated users, such as subscriber change them and perform Stored Cross-Site Scripting.


We have discovered 1,722 live websites that are affected by CVE-2023-4823.

Test my site




Affected Software

Product  Wp Meta And Date Remover
Category Wordpress Plugins
Vulnerable Domains1,722 live websites (100.00% of Wp Meta And Date Remover install base)
Vulnerable Versions
  • from 0 before 2.2
Vulnerable Versions Count2 versions ( 100.00% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Oct 31, 2023
  • Updated - Aug 2, 2024

Credits

  • dc11 (finder)
  • WPScan (coordinator)

CVE-2023-4823 usage by Country

United States636 websites



France215 websites
Germany141 websites
Poland111 websites
GB66 websites
Vietnam56 websites
Cyprus43 websites
Netherlands43 websites
Italy43 websites
Denmark33 websites

CVE-2023-4823 usage by TLD

.com780 websites
.org139 websites
.pl75 websites
.net65 websites
.de54 websites
.nl42 websites
.it42 websites
.co.uk35 websites
.fr27 websites
.ru25 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2023-4823

Top websites that are affected by CVE-2023-4823. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******.app United States**,***
***.***.ph Philippines***,***
*************.it Italy***,***
***********.de Germany***,***
*******.org France***,***
***********.com United States***,***
*********.com United States***,***
***************.org France***,***
**********.top Cyprus***,***
***********.com United States***,***
See full domain list

FAQ

CVE-2023-4823 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Wp Meta And Date Remover
A total of 1,722 websites have been identified as vulnerable to CVE-2023-4823, discovered through global website indexing conducted by WebTechSurvey.
Wp Meta And Date Remover is susceptible to CVE-2023-4823 vulnerability.
Wp Meta And Date Remover versions before 2.2 are vulnerable to CVE-2023-4823.
Version 2.2 of Wp Meta And Date Remover addresses the CVE-2023-4823 security vulnerability.