CVE-2023-5605

URL Shortify < 1.7.9.1 - Admin+ Stored XSS

The URL Shortify WordPress plugin before 1.7.9.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)


We have discovered 281 live websites that are affected by CVE-2023-5605.

Run a Free Instant Scan




Affected Software

Product  Url Shortify
Category Wordpress Plugins
Vulnerable Domains281 live websites (6.12% of Url Shortify install base)
Vulnerable Versions
  • from 0 through 1.7.9.1
Vulnerable Versions Count35 versions ( 45% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Nov 6, 2023
  • Updated - Aug 2, 2024

Credits

  • Bartlomiej Marek and Tomasz Swiadek (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2023-5605
United States74 websites



Germany39 websites
Spain20 websites
France16 websites
Russia13 websites
Italy10 websites
Poland10 websites
Iran8 websites
Brazil6 websites
Canada6 websites

Website Distribution by TLD

Number of websites using CVE-2023-5605
.com122 websites
.de17 websites
.org16 websites
.net11 websites
.ru10 websites
.pl7 websites
.it6 websites
.at4 websites
.eu3 websites
.nl3 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2023-5605

Top websites that are affected by CVE-2023-5605. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***************.de Germany**,***
******.com Germany***,***
***.tv United States***,***
**************.pro Poland***,***
***********.com Canada***,***
*******.**.in India*,***,***
************.*******.com France*,***,***
*******.de Germany*,***,***
************.pl Poland*,***,***
*********.de Germany*,***,***
See full domain list

FAQ

CVE-2023-5605 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Url Shortify
A total of 281 websites have been identified as vulnerable to CVE-2023-5605, based on global website indexing conducted by WebTechSurvey.
The Url Shortify is affected by the CVE-2023-5605 vulnerability.
Url Shortify versions up to 1.7.9.1 are vulnerable to CVE-2023-5605.
CVE-2023-5605 is resolved in version 1.7.9.1 of Url Shortify.