CVE-2023-51533


WordPress Ecwid Shopping Cart Plugin <= 6.12.4 is vulnerable to Cross Site Request Forgery (CSRF)

Cross-Site Request Forgery (CSRF) vulnerability in Ecwid Ecommerce Ecwid Ecommerce Shopping Cart.This issue affects Ecwid Ecommerce Shopping Cart: from n/a through 6.12.4.



We have discovered 989 live websites that are affected by CVE-2023-51533.

Contact us to get more info




Affected Software

Product  Ecwid Ecommerce Shopping Cart
Category Wordpress Plugins
Vulnerable Versions
  • from 0 through 6.12.4
Total Vulnerable Versions124
Vulnerable Domains989 live websites (35.15% of Ecwid Ecommerce Shopping Cart install base)


Common Weakness Enumeration


CWE-352 Cross-Site Request Forgery (CSRF)


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2023-51533 and the relative popularity of websites


Details

  • Published - Feb 28, 2024
  • Updated - Feb 28, 2024

Credits

  • Brandon Roldan (Patchstack Alliance) (finder)





Countries

United States506 websites



GB72 websites
Germany69 websites
Italy45 websites
Canada41 websites
Australia32 websites
Russia30 websites
France24 websites
Netherlands19 websites
South Africa16 websites

TLDs

.com581 websites
.org90 websites
.co.uk40 websites
.de32 websites
.it26 websites
.com.au26 websites
.net19 websites
.ru17 websites
.nl15 websites
.ca15 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2023-51533 through included software libraries and plugins.



References


Websites affected by CVE-2023-51533

Top websites that are affected by CVE-2023-51533. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
***.****.org United States***,***
**************.com United States***,***
*********.com ***,***
***.*************************.org United States***,***
*************.org United States***,***
*****************.org United States***,***
***.*********.com United States***,***
**********************.com Cyprus***,***
********.com Russia***,***
******************.org United States***,***
See full domain list