The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'et_pb_text' shortcode in all versions up to, and including, 4.23.1 due to insufficient input sanitization and output escaping on user supplied custom field data. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 345,473 live websites that are affected by CVE-2023-6744.
Product | ![]() |
Category | Wordpress Themes |
Vulnerable Domains | 345,473 live websites (36.85% of Divi install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 566 versions ( 92.79% of all versions) |
![]() | 136,685 websites |
![]() | 40,323 websites |
![]() | 26,955 websites |
![]() | 16,576 websites |
![]() | 12,712 websites |
![]() | 11,908 websites |
![]() | 9,164 websites |
![]() | 7,761 websites |
![]() | 7,133 websites |
![]() | 6,959 websites |
.com | 152,929 websites |
.de | 21,599 websites |
.org | 15,139 websites |
.co.uk | 13,880 websites |
.nl | 12,739 websites |
.fr | 11,017 websites |
.com.au | 8,758 websites |
.pl | 7,299 websites |
.net | 6,793 websites |
.es | 6,536 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
******.com | ![]() | *,*** | |
*******.com | ![]() | *,*** | |
****.ro | ![]() | *,*** | |
************.org | ![]() | *,*** | |
****************.com | ![]() | *,*** | |
******.com | ![]() | *,*** | |
******.com | ![]() | *,*** | |
***************.com | ![]() | **,*** | |
**************.de | ![]() | **,*** | |
***************.pl | ![]() | **,*** |