CVE-2023-6292


Ecwid Ecommerce Shopping Cart < 6.12.5 - Arbitrary Plugin Settings Change via CSRF

The Ecwid Ecommerce Shopping Cart WordPress plugin before 6.12.5 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.



We have discovered 989 live websites that are affected by CVE-2023-6292.

Contact us to get more info




Affected Software

Product  Ecwid Ecommerce Shopping Cart
Category Wordpress Plugins
Vulnerable Versions
  • from 0 before 6.12.5
Total Vulnerable Versions124
Vulnerable Domains989 live websites (35.15% of Ecwid Ecommerce Shopping Cart install base)


Common Weakness Enumeration


CWE-352 Cross-Site Request Forgery (CSRF)


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2023-6292 and the relative popularity of websites


Details

  • Published - Jan 16, 2024
  • Updated - Jan 16, 2024

Credits

  • Krzysztof Zając (CERT PL) (finder)
  • WPScan (coordinator)





Countries

United States506 websites



GB72 websites
Germany69 websites
Italy45 websites
Canada41 websites
Australia32 websites
Russia30 websites
France24 websites
Netherlands19 websites
South Africa16 websites

TLDs

.com581 websites
.org90 websites
.co.uk40 websites
.de32 websites
.it26 websites
.com.au26 websites
.net19 websites
.ru17 websites
.nl15 websites
.ca15 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2023-6292 through included software libraries and plugins.



References


Websites affected by CVE-2023-6292

Top websites that are affected by CVE-2023-6292. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
***.****.org United States***,***
**************.com United States***,***
*********.com ***,***
***.*************************.org United States***,***
*************.org United States***,***
*****************.org United States***,***
***.*********.com United States***,***
**********************.com Cyprus***,***
********.com Russia***,***
******************.org United States***,***
See full domain list