CVE-2023-6382

Master Slider - Responsive Touch Slider <= 3.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ms_slide' shortcode in all versions up to, and including, 3.9.9 due to insufficient input sanitization and output escaping on user supplied 'css_class' attribute. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.


We have discovered 68,318 live websites that are affected by CVE-2023-6382.

Test my site




Affected Software

Product  Master Slider
Category Wordpress Plugins
Vulnerable Domains68,318 live websites (97.05% of Master Slider install base)
Vulnerable Versions
  • from 0 through 3.9.9
Vulnerable Versions Count124 versions ( 99.20% of all versions)



Details

  • Published - Jun 1, 2024
  • Updated - Aug 2, 2024

Credits

  • Rafshanzani Suhada (finder)

CVE-2023-6382 usage by Country

United States22,414 websites



Germany8,875 websites
France4,663 websites
GB2,639 websites
Italy2,001 websites
Japan1,963 websites
Netherlands1,929 websites
Russia1,839 websites
Spain1,814 websites
Poland1,643 websites

CVE-2023-6382 usage by TLD

.com30,138 websites
.de4,385 websites
.org2,634 websites
.co.uk1,916 websites
.nl1,756 websites
.it1,646 websites
.fr1,525 websites
.com.br1,499 websites
.ru1,479 websites
.net1,364 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2023-6382

Top websites that are affected by CVE-2023-6382. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.org United States**,***
*********************.com United States**,***
*************.jp Japan**,***
********.tv United States**,***
*******.org United States**,***
*****.com United States**,***
*************.com United States**,***
***************.org United States**,***
******.org United States**,***
****.org United States**,***
See full domain list

FAQ

A total of 68,318 websites have been identified as vulnerable to CVE-2023-6382, discovered through global website indexing conducted by WebTechSurvey.
Master Slider is susceptible to CVE-2023-6382 vulnerability.
Master Slider versions before, and including, 3.9.9 are vulnerable to CVE-2023-6382.