CVE-2023-4925


Easy Forms for Mailchimp <= 6.8.10 - Admin+ Stored Cross-Site Scripting

The Easy Forms for Mailchimp WordPress plugin through 6.8.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed



We have discovered 3,957 live websites that are affected by CVE-2023-4925.

Contact us to get more info




Affected Software

Product  Easy Forms for Mailchimp
Category Wordpress Plugins
Vulnerable Versions
  • from 0 through 6.8.10
Total Vulnerable Versions64
Vulnerable Domains3,957 live websites (79.75% of Easy Forms for Mailchimp install base)


Common Weakness Enumeration


CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2023-4925 and the relative popularity of websites


Details

  • Published - Jan 15, 2024
  • Updated - Jan 15, 2024

Credits

  • Sławomir Zakrzewski (AFINE) (finder)
  • WPScan (coordinator)





Countries

United States1,495 websites



Italy353 websites
GB284 websites
Germany175 websites
Australia158 websites
France147 websites
Canada146 websites
Netherlands146 websites
Spain114 websites
Switzerland69 websites

TLDs

.com1,920 websites
.org311 websites
.it223 websites
.co.uk147 websites
.com.au104 websites
.nl101 websites
.net82 websites
.de73 websites
.ca63 websites
.fr56 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2023-4925 through included software libraries and plugins.



References


Websites affected by CVE-2023-4925

Top websites that are affected by CVE-2023-4925. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
************.com United States**,***
*************.org United States**,***
***.********.com United States**,***
*************.com United States**,***
******.********.com United States**,***
*****.com United States**,***
***.*****.com United States**,***
************.com United States**,***
***.*****.com Canada***,***
*********.net United States***,***
See full domain list