The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ms_slide' shortcode in all versions up to, and including, 3.9.9 due to insufficient input sanitization and output escaping on user supplied 'css_class' attribute. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 68,318 live websites that are affected by CVE-2023-6382.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 68,318 live websites (97.05% of Master Slider install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 124 versions ( 99.20% of all versions) |
![]() | 22,414 websites |
![]() | 8,875 websites |
![]() | 4,663 websites |
![]() | 2,639 websites |
![]() | 2,001 websites |
![]() | 1,963 websites |
![]() | 1,929 websites |
![]() | 1,839 websites |
![]() | 1,814 websites |
![]() | 1,643 websites |
.com | 30,138 websites |
.de | 4,385 websites |
.org | 2,634 websites |
.co.uk | 1,916 websites |
.nl | 1,756 websites |
.it | 1,646 websites |
.fr | 1,525 websites |
.com.br | 1,499 websites |
.ru | 1,479 websites |
.net | 1,364 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*********.org | ![]() | **,*** | |
*********************.com | ![]() | **,*** | |
*************.jp | ![]() | **,*** | |
********.tv | ![]() | **,*** | |
*******.org | ![]() | **,*** | |
*****.com | ![]() | **,*** | |
*************.com | ![]() | **,*** | |
***************.org | ![]() | **,*** | |
******.org | ![]() | **,*** | |
****.org | ![]() | **,*** |
FAQ