The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the map id parameter in all versions up to, and including, 9.0.28 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
We have discovered 21,260 live websites that are affected by CVE-2023-6697.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 21,260 live websites (42.47% of WP Go Maps install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 352 versions ( 93.12% of all versions) |
![]() | 6,100 websites |
![]() | 2,982 websites |
![]() | 1,860 websites |
![]() | 1,215 websites |
![]() | 1,099 websites |
![]() | 719 websites |
![]() | 717 websites |
![]() | 479 websites |
![]() | 449 websites |
![]() | 443 websites |
.com | 7,726 websites |
.de | 1,747 websites |
.pl | 1,011 websites |
.co.uk | 939 websites |
.fr | 872 websites |
.org | 732 websites |
.nl | 705 websites |
.it | 584 websites |
.com.au | 504 websites |
.ch | 405 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
***********************.com | ![]() | **,*** | |
******.net | ![]() | **,*** | |
**********.com | ![]() | **,*** | |
********.org | ![]() | **,*** | |
***************.com | ![]() | **,*** | |
**************.org | ![]() | ***,*** | |
*********************.net | ![]() | ***,*** | |
******.**.edu | ![]() | ***,*** | |
******.eu | ![]() | ***,*** | |
********.io | ![]() | ***,*** |
FAQ