CVE-2023-5558


LearnPress < 4.2.5.5 - Reflected Cross-Site Scripting

The LearnPress WordPress plugin before 4.2.5.5 does not sanitise and escape user input before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.



We have discovered 3,856 live websites that are affected by CVE-2023-5558.

Contact us to get more info




Affected Software

Product  LearnPress
Category Wordpress Plugins
Vulnerable Versions
  • from 0 before 4.2.5.5
Total Vulnerable Versions156
Vulnerable Domains3,856 live websites (44.39% of LearnPress install base)


Common Weakness Enumeration


CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Jan 16, 2024
  • Updated - Jan 16, 2024

Credits

  • Vitor Pacheco (finder)
  • WPScan (coordinator)





Countries

United States808 websites



India321 websites
France210 websites
Italy194 websites
Germany180 websites
Spain171 websites
Brazil154 websites
GB127 websites
Poland109 websites
Russia106 websites

TLDs

.com1,585 websites
.org256 websites
.it138 websites
.com.br126 websites
.net81 websites
.ru76 websites
.pl75 websites
.fr65 websites
.es61 websites
.de60 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


References


Websites affected by CVE-2023-5558

Top websites that are affected by CVE-2023-5558. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.org United States**,***
**************************.org United States***,***
***.********************.fr France***,***
***.********.***.my Malaysia***,***
*******.com Canada***,***
*********.org Belgium***,***
***.****.associates United States***,***
****************.com United Arab Emirates***,***
***.************.com Denmark***,***
***.**********************.org France***,***
See full domain list