CVE-2023-6744

Divi <= 4.23.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'et_pb_text' shortcode in all versions up to, and including, 4.23.1 due to insufficient input sanitization and output escaping on user supplied custom field data. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.


We have discovered 223,838 live websites that are affected by CVE-2023-6744.

Run a Free Instant Scan




Affected Software

Product  Divi
Category Wordpress Themes
Vulnerable Domains223,838 live websites (28% of Divi install base)
Vulnerable Versions
  • from 0 through 4.23.1
Vulnerable Versions Count347 versions ( 95% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Dec 23, 2023
  • Updated - Apr 8, 2026

Credits

  • Francesco Carlucci (finder)

Website Distribution by Country

Number of websites using CVE-2023-6744
United States70,051 websites



Germany23,971 websites
France15,743 websites
GB12,680 websites
Spain10,021 websites
Netherlands9,611 websites
Italy9,065 websites
Poland6,327 websites
Canada5,761 websites
Australia5,219 websites

Website Distribution by TLD

Number of websites using CVE-2023-6744
.com94,739 websites
.de14,853 websites
.org9,607 websites
.nl8,646 websites
.co.uk8,511 websites
.fr7,342 websites
.it6,210 websites
.pl4,844 websites
.com.au4,683 websites
.es4,511 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2023-6744

Top websites that are affected by CVE-2023-6744. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******.com United States*,***
***************.com Spain**,***
**************.de Germany**,***
**************.org Switzerland**,***
******.fr France**,***
***************.com United States**,***
***********************.pl Poland**,***
*********.com United States**,***
************.com Germany**,***
***************.com United States**,***
See full domain list

FAQ

CVE-2023-6744 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Divi
A total of 223,838 websites have been identified as vulnerable to CVE-2023-6744, based on global website indexing conducted by WebTechSurvey.
The Divi is affected by the CVE-2023-6744 vulnerability.
Divi versions up to and including 4.23.1 are vulnerable to CVE-2023-6744.