CVE-2023-50880


WordPress BuddyPress Plugin <= 11.3.1 is vulnerable to Cross Site Scripting (XSS)

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in The BuddyPress Community BuddyPress allows Stored XSS.This issue affects BuddyPress: from n/a through 11.3.1.



We have discovered 15,456 live websites that are affected by CVE-2023-50880.

Contact us to get more info




Affected Software

Product  BuddyPress
Category Message Boards
Vulnerable Versions
  • from 0 through 11.3.1
Total Vulnerable Versions109
Vulnerable Domains15,456 live websites (78.78% of BuddyPress install base)


Common Weakness Enumeration


CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2023-50880 and the relative popularity of websites


Details

  • Published - Dec 29, 2023
  • Updated - Dec 29, 2023

Credits

  • Rafie Muhammad (Patchstack) (finder)





Countries

United States5,108 websites



Germany1,217 websites
France1,111 websites
Italy739 websites
Russia577 websites
GB558 websites
Spain465 websites
Netherlands369 websites
Japan367 websites
Canada310 websites

TLDs

.com6,411 websites
.org1,626 websites
.de606 websites
.net544 websites
.it470 websites
.ru443 websites
.fr402 websites
.nl263 websites
.co.uk219 websites
.com.br216 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2023-50880 through included software libraries and plugins.



References


Websites affected by CVE-2023-50880

Top websites that are affected by CVE-2023-50880. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
***.*******.org United States*,***
***.******.com Singapore**,***
*********.*******.org United States**,***
***.**************.org United States**,***
*****.*****.edu United States**,***
*******.space United States**,***
*****.***.uk GB**,***
****.com United States**,***
***.**********.org Netherlands**,***
*****.io United States**,***
See full domain list