CVE-2023-50370

WordPress Livemesh Addons for WPBakery Page Builder Plugin <= 3.5 is vulnerable to Cross Site Scripting (XSS)

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Livemesh WPBakery Page Builder Addons by Livemesh allows Stored XSS.This issue affects WPBakery Page Builder Addons by Livemesh: from n/a through 3.5.


We have discovered 1,994 live websites that are affected by CVE-2023-50370.

Run a Free Instant Scan




Affected Software

Product  Addons For Visual Composer
Category Wordpress Plugins
Vulnerable Domains1,994 live websites (30% of Addons For Visual Composer install base)
Vulnerable Versions
  • from 0 through 3.5
Vulnerable Versions Count38 versions ( 81% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Dec 14, 2023
  • Updated - Aug 2, 2024

Credits

  • Abu Hurayra (Patchstack Alliance) (finder)

Website Distribution by Country

Number of websites using CVE-2023-50370
United States399 websites



Italy185 websites
Germany184 websites
France139 websites
Russia111 websites
GB75 websites
Spain70 websites
Poland47 websites
Brazil38 websites
Netherlands37 websites

Website Distribution by TLD

Number of websites using CVE-2023-50370
.com759 websites
.it126 websites
.org103 websites
.ru84 websites
.de81 websites
.net50 websites
.fr44 websites
.com.br36 websites
.pl32 websites
.co.uk32 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2023-50370

Top websites that are affected by CVE-2023-50370. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.org United States***,***
*****************.com United States***,***
*****************.org United States***,***
***********.org France***,***
*****.ca Canada***,***
***********.***.uk GB***,***
*************.org Spain***,***
***.**.rs Serbia***,***
************.eu Austria***,***
*********.com Indonesia***,***
See full domain list

FAQ

CVE-2023-50370 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Addons For Visual Composer
A total of 1,994 websites have been identified as vulnerable to CVE-2023-50370, based on global website indexing conducted by WebTechSurvey.
The Addons For Visual Composer is affected by the CVE-2023-50370 vulnerability.
Addons For Visual Composer versions up to and including 3.5 are vulnerable to CVE-2023-50370.