CVE-2023-50889

WordPress Beaver Builder Plugin <= 2.7.2 is vulnerable to Cross Site Scripting (XSS)

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in The Beaver Builder Team Beaver Builder – WordPress Page Builder allows Stored XSS.This issue affects Beaver Builder – WordPress Page Builder: from n/a through 2.7.2.


We have discovered 46,166 live websites that are affected by CVE-2023-50889.

Test my site




Affected Software

Product  Beaver Builder
Category Wordpress Plugins
Vulnerable Domains46,166 live websites (31.18% of Beaver Builder install base)
Vulnerable Versions
  • from 0 through 2.7.2
Vulnerable Versions Count282 versions ( 86.50% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Dec 29, 2023
  • Updated - Aug 2, 2024

Credits

  • Rafie Muhammad (Patchstack) (finder)

CVE-2023-50889 usage by Country

United States32,382 websites



Germany1,846 websites
Japan1,617 websites
GB1,587 websites
France1,073 websites
Singapore957 websites
China778 websites
Australia722 websites
Netherlands615 websites
Canada429 websites

CVE-2023-50889 usage by TLD

.com31,785 websites
.org2,434 websites
.co.uk1,279 websites
.net1,159 websites
.com.au1,019 websites
.de968 websites
.ca785 websites
.nl656 websites
.jp456 websites
.fr318 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2023-50889

Top websites that are affected by CVE-2023-50889. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**************.com United States**,***
****.ca United States**,***
**********.com United States**,***
**********.com United States**,***
**********.com United States**,***
************.com United States**,***
*********.com United States**,***
********.com United States***,***
*****.com United States***,***
***********.org United States***,***
See full domain list

FAQ

CVE-2023-50889 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Beaver Builder
A total of 46,166 websites have been identified as vulnerable to CVE-2023-50889, discovered through global website indexing conducted by WebTechSurvey.
Beaver Builder is susceptible to CVE-2023-50889 vulnerability.
Beaver Builder versions before, and including, 2.7.2 are vulnerable to CVE-2023-50889.